CVE List

Id CVE No. Status Description Phase Votes Comments Actions
225  CVE-1999-0226  Candidate  Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.  Proposed (19990728)  ACCEPT(1) Northcutt | MODIFY(1) Frech | NOOP(1) Baker | REJECT(1) Christey  Christey> Too general, and no references. | Frech> XF:nt-frag(528) | See reference from BugTraq Mailing List, "A New Fragmentation Attack" at | http://www.securityfocus.com/templates/archive.pike?list=1&date=1997-07-8&ms | g=Pine.SUN.3.94.970710054440.11707A-100000@dfw.dfw.net  View
224  CVE-1999-0225  Entry  Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.        View
223  CVE-1999-0224  Entry  Denial of service in Windows NT messenger service through a long username.        View
222  CVE-1999-0223  Entry  Solaris syslogd crashes when receiving a message from a host that doesn"t have an inverse DNS entry.        View
221  CVE-1999-0222  Candidate  Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.  Proposed (19990714)  ACCEPT(1) Baker | MODIFY(3) Frech, Levy, Shostack | NOOP(3) Balinsky, Northcutt, Wall | RECAST(1) Ziese | REJECT(1) Christey  Shostack> I follow cisco announcements and problems pretty closely, and haven"t | seen this. Source? | Frech> XF:cisco-web-crash | Christey> XF:cisco-web-crash has no additional references. I can"t find | any references in Bugtraq or Cisco either. This bug is | supposedly tested by at least one security product, but that | product"s database doesn"t have any references either. So | a question becomes, how did it make it into at least two | security companies" databases? | Levy> BUGTGRAQ: http://www.securityfocus.com/archive/1/60159 | BID 1154 | Ziese> The vulnerability is addressed by a vendor acknowledgement. This one, if | recast to reflect that "...after using a long url..." should be replaced | with | "...A defect in multiple releases of Cisco IOS software will cause a Cisco | router or switch to halt and reload if the IOS HTTP service is enabled, | browsing to "http://router-ip/anytext?/" is attempted, and the enable | password is supplied when requested. This defect can be exploited to produce | a denial of service (DoS) attack." | Then I can accept this and mark it as "Verfied by my Company". If it can"t | be recast because this (long uri) is diffferent then our release (special | url construction). | CHANGE> [Christey changed vote from REVIEWING to REJECT] | Christey> Elias Levy"s suggested reference is CVE-2000-0380. | I don"t think that Kevin"s description is really addressing | this either. The lack of references and a specific | description make this candidate unusable, so it should be | rejected.  View

Page 20899 of 20943, showing 5 records out of 104715 total, starting on record 104491, ending on 104495

Actions