CVE List

Id CVE No. Status Description Phase Votes Comments Actions
219  CVE-1999-0220  Candidate  Attackers can do a denial of service of IRC by crashing the server.  Proposed (19990728)  NOOP(2) Baker, Northcutt | REJECT(2) Christey, Frech  Frech> Would reconsider if any references were available. | Christey> No references available, combined with extremely vague | description, equals REJECT.  View
239  CVE-1999-0240  Candidate  Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.  Proposed (19990728)  ACCEPT(1) Northcutt | NOOP(1) Baker | REJECT(1) Frech  Frech> Would reconsider if any references were available.  View
1263  CVE-1999-1283  Candidate  Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.  Proposed (20010912)  ACCEPT(2) Cole, Frech | NOOP(2) Foat, Wall  Frech> Will go along with a REJECT if MITRE decides on | EX-CLIENT-DOS.  View
487  CVE-1999-0489  Candidate  MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.  Modified (19991205-01)  ACCEPT(1) Levy | MODIFY(1) Wall | NOOP(2) Baker, Ozancin | RECAST(1) Prosser | REJECT(1) Christey | REVIEWING(1) Frech  Frech> Wasn"t Untrusted scripted paste MS98-015? I can find no mention of a | clipboard in either. | I cannot proceed on this one without further clarification. | Wall> (source: MS:MS99-012) | Prosser> agree with Andre here. The Untrusted Scripted paste | vulnerability was originally addressed in MS98-015 and it is in the file | upload intrinsic control in which an attacker can paste the name of a file | on the target"s drive in the control and a form submission would then send | that file from the attacked machine to the remote web site. This one has | nothing to do with the clipboard. What the advisory mentioned here, | MS99-012, does is replace the MSHTML parsing engine which is supposed to fix | the original Untrusted Scripted Paste issue and a variant, as well as the | two Cross-Frame variants and a privacy issue in IMG SRC. | The vulnerability that allowed reading of a user"s clipboard is the Forms | 2.0 Active X control vulnerability discussed in MS99-01 | Christey> The advisory should have been listed as MS99-012. | CVE-1999-0468 describes the untrusted scripted paste problem | in MS99-012. | Frech> Pending response to guidance request. 12/6/01.  View
583  CVE-1999-0601  Candidate  A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.  Proposed (19990726)  ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey  Frech> Waiting for Godot, er, CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html  View

Page 218 of 20943, showing 5 records out of 104715 total, starting on record 1086, ending on 1090

Actions