CVE List

Id CVE No. Status Description Phase Votes Comments Actions
679  CVE-1999-0698  Candidate  Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.  Proposed (19991222)  ACCEPT(6) Armstrong, Baker, Blake, Cole, Collins, Ozancin | MODIFY(1) Frech | NOOP(4) Landfield, Levy, Stracener, Wall | REJECT(1) Christey  Stracener> Is the candidate referring to the denial of service problem mentioned in | the | changelogs for versions previous to 1.4.3-1 or does it pertain to some | problem with or | 1.4.8-1? | Frech> Depending on the version, this could be any number of DoSes | related to ippl. | From http://www.larve.net/ippl/: | 9 April 1999: version 1.4.3 released, correctly fixing a | potential denial of service attack. | 7 April 1999: version 1.4.2 released, fixing a potential | denial of service attack. | XF:linux-ippl-dos | Christey> Changelog: http://pltplp.net/ippl/docs/HISTORY | | See comments for version 1.4.2 and 1.4.3 | Another source: http://freshmeat.net/news/1999/04/08/923586598.html | CHANGE> [Stracener changed vote from REVIEWING to NOOP] | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> As mentioned by others, this could apply to several different | versions. Since the description is too vague, this CAN should | be REJECTED and recast into other candidates.  View
973  CVE-1999-0993  Candidate  Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.  Proposed (19991222)  ACCEPT(2) Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Cole | REJECT(1) LeBlanc  Frech> XF:exchange-acl-changes(3916) | LeBlanc> Not a vulnerability  View
721  CVE-1999-0741  Candidate  QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.  Proposed (19991222)  ACCEPT(4) Baker, Frech, Levy, Stracener | NOOP(2) Christey, Oliver  Christey> change description - anyone can log on *as* root | Frech> (Note: this XF also cataloged under CVE-1999-0508.)  View
983  CVE-1999-1003  Candidate  War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.  Proposed (19991222)  ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:warftp-connection-flood  View
730  CVE-1999-0750  Candidate  Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user"s Hotmail account.  Proposed (19991222)  ACCEPT(1) Levy | MODIFY(2) Frech, Stracener | NOOP(1) Baker  Stracener> Many sites are vulnerable to this problem. I recommend removing the | explicit references to Hotmail and making the description more generic. | Suggest: Javascript can be injected using the STYLE tag in an HTML | formatted e-mail, allowing remote attackers to execute commands on user | accounts. | Frech> XF:hotmail-html-style-embed  View

Page 20558 of 20943, showing 5 records out of 104715 total, starting on record 102786, ending on 102790

Actions