CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1131 | CVE-1999-1151 | Candidate | Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
1132 | CVE-1999-1152 | Candidate | Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:microcom-brute-force(7301) | View |
1388 | CVE-1999-1408 | Candidate | Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Foat | Frech> XF: aix-hpux-connect-dos(7195) | Christey> BUGTRAQ:19970307 Re: Bug in connect() ? | URL:http://www.securityfocus.com/archive/1/Pine.HPP.3.92.970307195408.12139B-100000@wpax13.physik.uni-wuerzburg.de | BUGTRAQ:19970311 Re: Bug in connect() for aix 4.1.4 ? | URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=6419 | View |
1133 | CVE-1999-1153 | Candidate | HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | View | |
1134 | CVE-1999-1154 | Candidate | LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(3) Christey, Foat, Wall | Christey> I confirmed this problem via visual inspection of the | source code in http://www.lakeweb.com/scripts/filemail.zip | Line 82 has an insufficient check for shell metacharacters | that doesn"t exclude semicolons. Line 129 is the | call where the metacharacters are injected. | | Need to add "filemail.pl" to the description. | View |
Page 20696 of 20943, showing 5 records out of 104715 total, starting on record 103476, ending on 103480