CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
219 | CVE-1999-0220 | Candidate | Attackers can do a denial of service of IRC by crashing the server. | Proposed (19990728) | NOOP(2) Baker, Northcutt | REJECT(2) Christey, Frech | Frech> Would reconsider if any references were available. | Christey> No references available, combined with extremely vague | description, equals REJECT. | View |
239 | CVE-1999-0240 | Candidate | Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy. | Proposed (19990728) | ACCEPT(1) Northcutt | NOOP(1) Baker | REJECT(1) Frech | Frech> Would reconsider if any references were available. | View |
1263 | CVE-1999-1283 | Candidate | Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall | Frech> Will go along with a REJECT if MITRE decides on | EX-CLIENT-DOS. | View |
487 | CVE-1999-0489 | Candidate | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | Modified (19991205-01) | ACCEPT(1) Levy | MODIFY(1) Wall | NOOP(2) Baker, Ozancin | RECAST(1) Prosser | REJECT(1) Christey | REVIEWING(1) Frech | Frech> Wasn"t Untrusted scripted paste MS98-015? I can find no mention of a | clipboard in either. | I cannot proceed on this one without further clarification. | Wall> (source: MS:MS99-012) | Prosser> agree with Andre here. The Untrusted Scripted paste | vulnerability was originally addressed in MS98-015 and it is in the file | upload intrinsic control in which an attacker can paste the name of a file | on the target"s drive in the control and a form submission would then send | that file from the attacked machine to the remote web site. This one has | nothing to do with the clipboard. What the advisory mentioned here, | MS99-012, does is replace the MSHTML parsing engine which is supposed to fix | the original Untrusted Scripted Paste issue and a variant, as well as the | two Cross-Frame variants and a privacy issue in IMG SRC. | The vulnerability that allowed reading of a user"s clipboard is the Forms | 2.0 Active X control vulnerability discussed in MS99-01 | Christey> The advisory should have been listed as MS99-012. | CVE-1999-0468 describes the untrusted scripted paste problem | in MS99-012. | Frech> Pending response to guidance request. 12/6/01. | View |
583 | CVE-1999-0601 | Candidate | A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets. | Proposed (19990726) | ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey | Frech> Waiting for Godot, er, CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html | View |
Page 218 of 20943, showing 5 records out of 104715 total, starting on record 1086, ending on 1090