CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2725  CVE-2000-1158  Candidate  NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.  Proposed (20001219)  MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:sniffer-agent-weak-authentication(5951)  View
1911  CVE-2000-0333  Candidate  tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.  Proposed (20000518)  ACCEPT(3) Armstrong, Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:sniffer-dns-decode-dos  View
1921  CVE-2000-0343  Candidate  Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.  Proposed (20000518)  ACCEPT(2) Cole, Levy | MODIFY(2) Christey, Frech | NOOP(2) Armstrong, Wall  Frech> XF:sniffit-lmail-bo | Christey> This issue was rediscovered. | ADDREF BUGTRAQ:20020119 remote buffer overflow in sniffit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101167452712383&w=2 | ADDREF BUGTRAQ:20000525 `sniffit -L mail" vulnerabilities | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95928090612990&w=2 | | I reviewed the patch that was claimed in the 20020119 Bugtraq | post, and it could well address the issue. However, since the | patch is also dated around the time of the original Bugtraq | post, *and* it says that it"s addressing an issue that"s | discussed on Bugtraq, that is sufficient to establish | acknowledgement. | CHANGE> [Christey changed vote from NOOP to MODIFY] | Christey> XF:sniffit-normmail-l-bo(7933) | URL:http://www.iss.net/security_center/static/7933.php  View
513  CVE-1999-0516  Candidate  An SNMP community name is guessable.  Proposed (19990714)  ACCEPT(4) Baker, Meunier, Northcutt, Shostack | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:snmp-get-guess | XF:snmp-set-guess | XF:sol-hidden-commstr | XF:hpov-hidden-snmp-comm | Christey> This candidate is affected by the CD:CF-PASS content decision, | which determines the appropriate level of abstraction to | use for password problems. CD:CF-PASS needs to be accepted | by the Editorial Board before this candidate can be | converted into a CVE entry; the final version of CD:CF-PASS | may require using a different LOA than this candidate is | currently using.  View
591  CVE-1999-0609  Candidate  An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information.  Proposed (19990728)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Christey, Northcutt, Wall  Frech> XF:softcart-misconfig(3856) | Christey> Consider adding BID:2055  View

Page 20860 of 20943, showing 5 records out of 104715 total, starting on record 104296, ending on 104300

Actions