CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1493  CVE-1999-1513  Candidate  Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities.  Proposed (20010912)  NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech  Frech> (ACCEPT; Task 2355)  View
3740  CVE-2001-0934  Candidate  Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.  Proposed (20020131)  ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Wall  Frech> (ACCEPT; Task 2353) | Christey> Rediscovered in: | BUGTRAQ:20020211 PowerFTP Personal FTP Server Multiple Vulnerabilities | http://marc.theaimsgroup.com/?l=bugtraq&m=101361745222207&w=2 | This rediscovery says the problem is in 2.10. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:powerftp-pwd-path-disclosure(8182) | Christey> BID:4072 | URL:http://online.securityfocus.com/bid/4072  View
3725  CVE-2001-0919  Candidate  Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript.  Modified (20040811)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall  Frech> (ACCEPT: Task 2352) | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ie-cookie-prompt-bypass(8621) | Christey> Add period to the end of the description.  View
98  CVE-1999-0098  Candidate  Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.  Proposed (19990726)  MODIFY(2) Baker, Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> (Accept XF reference.) | Our references do not mention hiding activities. This issue can crash the | SMTP server or execute arbitrary byte-code. Is there another reference | available? | Christey> Should this be merged with CVE-1999-0284, which is Sendmail | with SMTP HELO? | Christey> BUGTRAQ:19980522 about sendmail 8.8.8 HELO hole | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925991&w=2 | BUGTRAQ:19980527 about sendmail 8.8.8 HELO hole | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101926003&w=2 | Baker> Apparently this XF reference is not for this issue, but for the other issue. This should be modified to have the Bugtraq references, and remove the XF reference.  View
283  CVE-1999-0284  Candidate  Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.  Proposed (19990623)  ACCEPT(2) Blake, Northcutt | MODIFY(3) Frech, Levy, Ozancin | NOOP(1) Baker | REVIEWING(1) Christey  Frech> "Windows NT-based mail servers" (A trademark thing, and for clarification) | XF:mdaemon-helo-bo | XF:lotus-notes-helo-crash | XF:slmail-helo-overflow | XF:smtp-helo-bo (mentions several products) | XF:smtp-exchangedos | Levy> - Need one per software. Each one should be its own | vulnerability. | Ozancin> => Windows NT is correct | Christey> These are probably multiple codebases, so we"ll need to use | dot notation. Also need to see if this should be merged | with CVE-1999-0098 (Sendmail SMTP HELO).  View

Page 245 of 20943, showing 5 records out of 104715 total, starting on record 1221, ending on 1225

Actions