CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2685  CVE-2000-1118  Candidate  24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:24link-bypass-authentication(5930)  View
1280  CVE-1999-1300  Candidate  Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.  Proposed (20010912)  ACCEPT(4) Armstrong, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF: unicos-accton-read-files(7210)  View
15  CVE-1999-0015  Candidate  Teardrop IP denial of service.  Modified (20090302)  ACCEPT(1) Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF: teardrop-mod | Christey> Not sure how many separate "instances" of Teardrop there are. | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> MSKB:Q154174 | MSKB:Q154174 (CVE-1999-0015) and MSKB:Q179129 (CVE-1999-0104) | indicate that CVE-1999-0015 was fixed in NT SP3, but | CVE-1999-0104 was not. Thus CD:SF-LOC suggests that the | problems keep separate candidates because one problem appears | in a different version than the other. | Christey> BID:124 | http://www.securityfocus.com/bid/124 | Consider MSKB:Q154174 | http://support.microsoft.com/support/kb/articles/q154/1/74.asp | Consider BUGTRAQ:19971113 Linux IP fragment overlap bug | http://www.securityfocus.com/archive/1/8014  View
3445  CVE-2001-0632  Candidate  Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.  Proposed (20010727)  ACCEPT(6) Baker, Bishop, Cole, Prosser, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF: chilisoft-asp-unauthorized-access(6957) | CHANGE> [Williams changed vote from ACCEPT to MODIFY] | Williams> there are actually several issues here, not just the one mentioned in our description. need to modify. | CHANGE> [Williams changed vote from MODIFY to ACCEPT] | Williams> NM my comments. just saw the other CANs. :/ | Prosser> | Vendor Response to issue: | Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities | http://www.securityfocus.com/archive/1/20010224172142.1888.qmail@securityfocus.com  View
1388  CVE-1999-1408  Candidate  Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Foat  Frech> XF: aix-hpux-connect-dos(7195) | Christey> BUGTRAQ:19970307 Re: Bug in connect() ? | URL:http://www.securityfocus.com/archive/1/Pine.HPP.3.92.970307195408.12139B-100000@wpax13.physik.uni-wuerzburg.de | BUGTRAQ:19970311 Re: Bug in connect() for aix 4.1.4 ? | URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=6419  View

Page 217 of 20943, showing 5 records out of 104715 total, starting on record 1081, ending on 1085

Actions