CVE List

Id CVE No. Status Description Phase Votes Comments Actions
442  CVE-1999-0443  Candidate  Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.  Proposed (19990728)  ACCEPT(1) Baker | MODIFY(1) Frech  Frech> Change "Patrol management software" to "The PATROL management product from | BMC Software".  View
449  CVE-1999-0450  Candidate  In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).  Modified (20090622)  ACCEPT(2) Ozancin, Wall | NOOP(2) Baker, Christey | REJECT(2) Frech, LeBlanc  Frech> Can"t find in database. | Christey> This looks like another discovery of CVE-2000-0071 | LeBlanc> - I just tried to repro this based on the BUGTRAQ vuln information, | and it does not repro - | GET /bogus.pl HTTP/1.0 | HTTP/1.1 404 Object Not Found | Server: Microsoft-IIS/5.0 | Date: Thu, 05 Oct 2000 21:04:20 GMT | Content-Length: 3243 | Content-Type: text/html | No path is returned whatsoever. This may have been a problem on some version | of IIS in the past, but the BUGTRAQ ID says all versions are vulnerable. | Let"s try and figure out what version had the problem, whether it is | intrinsic to IIS or the result of adding a 3rd party implementation of perl, | and when it got fixed, then we can try again. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Christey> Add "no-such-file.pl" as an example to the desc, to facilitate | search (it"s used by CGI scanners and in the original example)  View
399  CVE-1999-0400  Candidate  Denial of service in Linux 2.2.0 running the ldd command on a core file.  Modified (20000105-01)  ACCEPT(1) Baker | MODIFY(1) Frech  Frech> BUGTRAQ:Jan27,1999 | (http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-01-22& | msg=Pine.LNX.4.05.9901270538380.539-100000@vitelus.com) | XF:linux-kernel-ldd-dos  View
1494  CVE-1999-1514  Candidate  Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> BugTraq reference date seems to be 19991029; see | http://online.securityfocus.com/archive/1/33123  View
3975  CVE-2001-1171  Candidate  Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.  Proposed (20020315)  ACCEPT(1) Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese | REJECT(2) Christey, Frech  Frech> Both candidates assigned to XF:fw1-tmp-file-symlink(7094); | CVE-2001-1171 has subset of references in CVE-201-1102. | Christey> Agreed, it"s a dupe. CVE-2001-1102 will be preferred, since | it has more complete references.  View

Page 238 of 20943, showing 5 records out of 104715 total, starting on record 1186, ending on 1190

Actions