CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3171 | CVE-2001-0350 | Candidate | Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability. | Modified (20050509) | ACCEPT(5) Armstrong, Balinsky, Cole, Foat, Ziese | MODIFY(1) Frech | RECAST(1) Stracener | REVIEWING(2) Christey, Wall | Wall> Perhaps merge 0349 and 0350 unless there is a bigger difference. | Stracener> Merge this with 0349. | Frech> XF:win2k-telnet-pipe-privileges(6664) | Christey> CIAC:L-092 | URL:http://www.ciac.org/ciac/bulletins/l-092.shtml | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CERT-VN:VU#587587 | URL:http://www.kb.cert.org/vuls/id/587587 | BID:2849 | Microsoft identifies two separate vulnerabilities that are extremely | similar, but the security bulletin states that "The two | vulnerabilities differ primarily in the way they exploit the | underlying problem regarding named pipe creation." So, it may be | necessary to merge CVE-2001-0350 with CVE-2001-0349. | | If one issue is because of predictable names, and another | issue is because pipe ownership isn"t properly verified, then | these could stay SPLIT, and the descriptions should be | modified accordingly. | View |
257 | CVE-1999-0258 | Candidate | Bonk variation of teardrop IP fragmentation denial of service. | Proposed (19990726) | MODIFY(2) Frech, Wall | REVIEWING(1) Christey | Wall> Reference Q179129 | Frech> XF:teardrop-mod | Christey> Not sure how many separate "instances" of Teardrop there are. | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> BUGTRAQ:19980108 bonk.c | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88429524325956&w=2 | NTBUGTRAQ:19980108 bonk.c | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88433857200304&w=2 | NTBUGTRAQ:19980109 Re: Bonk.c | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88441302913269&w=2 | NTBUGTRAQ:19980304 Update on wide-spread NewTear Denial of Service attacks | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88901842000424&w=2 | BUGTRAQ:19980304 Update on wide-spread NewTear Denial of Service attacks | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88903296104349&w=2 | CIAC:I-031a | http://ciac.llnl.gov/ciac/bulletins/i-031a.shtml | | CERT summary CS-98.02 implies that bonk, boink, and newtear | all exploit the same vulnerability. | View |
467 | CVE-1999-0469 | Candidate | Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. | Proposed (19990728) | ACCEPT(1) Wall | NOOP(2) Baker, Northcutt | REJECT(3) Christey, Frech, LeBlanc | Wall> Reference: Microsoft Security Bulletin MS99-012 | Christey> DUPE CVE-1999-0488 | Frech> Defer to Christey"s vote. | However, XF:ie-mshtml-crossframe(2216) assigned to CVE-1999-0488. | LeBlanc> Duplicate | View |
457 | CVE-1999-0459 | Candidate | Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot. | Proposed (19990728) | ACCEPT(1) Frech | NOOP(2) Baker, Northcutt | REJECT(1) Wall | Wall> Reject based on beta copy. | View |
119 | CVE-1999-0119 | Candidate | Windows NT 4.0 beta allows users to read and delete shares. | Proposed (19990728) | MODIFY(1) Frech | NOOP(2) Baker, Northcutt | REJECT(1) Wall | Wall> Reject based on beta copy. | Frech> XF:nt-beta(11) | Reconsider reject, because this beta was in widespread use. | View |
Page 20936 of 20943, showing 5 records out of 104715 total, starting on record 104676, ending on 104680