CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
442 | CVE-1999-0443 | Candidate | Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password. | Proposed (19990728) | ACCEPT(1) Baker | MODIFY(1) Frech | Frech> Change "Patrol management software" to "The PATROL management product from | BMC Software". | View |
449 | CVE-1999-0450 | Candidate | In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | Modified (20090622) | ACCEPT(2) Ozancin, Wall | NOOP(2) Baker, Christey | REJECT(2) Frech, LeBlanc | Frech> Can"t find in database. | Christey> This looks like another discovery of CVE-2000-0071 | LeBlanc> - I just tried to repro this based on the BUGTRAQ vuln information, | and it does not repro - | GET /bogus.pl HTTP/1.0 | HTTP/1.1 404 Object Not Found | Server: Microsoft-IIS/5.0 | Date: Thu, 05 Oct 2000 21:04:20 GMT | Content-Length: 3243 | Content-Type: text/html | No path is returned whatsoever. This may have been a problem on some version | of IIS in the past, but the BUGTRAQ ID says all versions are vulnerable. | Let"s try and figure out what version had the problem, whether it is | intrinsic to IIS or the result of adding a 3rd party implementation of perl, | and when it got fixed, then we can try again. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Christey> Add "no-such-file.pl" as an example to the desc, to facilitate | search (it"s used by CGI scanners and in the original example) | View |
399 | CVE-1999-0400 | Candidate | Denial of service in Linux 2.2.0 running the ldd command on a core file. | Modified (20000105-01) | ACCEPT(1) Baker | MODIFY(1) Frech | Frech> BUGTRAQ:Jan27,1999 | (http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-01-22& | msg=Pine.LNX.4.05.9901270538380.539-100000@vitelus.com) | XF:linux-kernel-ldd-dos | View |
1494 | CVE-1999-1514 | Candidate | Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> BugTraq reference date seems to be 19991029; see | http://online.securityfocus.com/archive/1/33123 | View |
3975 | CVE-2001-1171 | Candidate | Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy. | Proposed (20020315) | ACCEPT(1) Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese | REJECT(2) Christey, Frech | Frech> Both candidates assigned to XF:fw1-tmp-file-symlink(7094); | CVE-2001-1171 has subset of references in CVE-201-1102. | Christey> Agreed, it"s a dupe. CVE-2001-1102 will be preferred, since | it has more complete references. | View |
Page 238 of 20943, showing 5 records out of 104715 total, starting on record 1186, ending on 1190