CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
679 | CVE-1999-0698 | Candidate | Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux. | Proposed (19991222) | ACCEPT(6) Armstrong, Baker, Blake, Cole, Collins, Ozancin | MODIFY(1) Frech | NOOP(4) Landfield, Levy, Stracener, Wall | REJECT(1) Christey | Stracener> Is the candidate referring to the denial of service problem mentioned in | the | changelogs for versions previous to 1.4.3-1 or does it pertain to some | problem with or | 1.4.8-1? | Frech> Depending on the version, this could be any number of DoSes | related to ippl. | From http://www.larve.net/ippl/: | 9 April 1999: version 1.4.3 released, correctly fixing a | potential denial of service attack. | 7 April 1999: version 1.4.2 released, fixing a potential | denial of service attack. | XF:linux-ippl-dos | Christey> Changelog: http://pltplp.net/ippl/docs/HISTORY | | See comments for version 1.4.2 and 1.4.3 | Another source: http://freshmeat.net/news/1999/04/08/923586598.html | CHANGE> [Stracener changed vote from REVIEWING to NOOP] | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> As mentioned by others, this could apply to several different | versions. Since the description is too vague, this CAN should | be REJECTED and recast into other candidates. | View |
973 | CVE-1999-0993 | Candidate | Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. | Proposed (19991222) | ACCEPT(2) Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Cole | REJECT(1) LeBlanc | Frech> XF:exchange-acl-changes(3916) | LeBlanc> Not a vulnerability | View |
721 | CVE-1999-0741 | Candidate | QMS CrownNet Unix Utilities for 2060 allows root to log on without a password. | Proposed (19991222) | ACCEPT(4) Baker, Frech, Levy, Stracener | NOOP(2) Christey, Oliver | Christey> change description - anyone can log on *as* root | Frech> (Note: this XF also cataloged under CVE-1999-0508.) | View |
983 | CVE-1999-1003 | Candidate | War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections. | Proposed (19991222) | ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:warftp-connection-flood | View |
730 | CVE-1999-0750 | Candidate | Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user"s Hotmail account. | Proposed (19991222) | ACCEPT(1) Levy | MODIFY(2) Frech, Stracener | NOOP(1) Baker | Stracener> Many sites are vulnerable to this problem. I recommend removing the | explicit references to Hotmail and making the description more generic. | Suggest: Javascript can be injected using the STYLE tag in an HTML | formatted e-mail, allowing remote attackers to execute commands on user | accounts. | Frech> XF:hotmail-html-style-embed | View |
Page 20558 of 20943, showing 5 records out of 104715 total, starting on record 102786, ending on 102790