CVE List

Id CVE No. Status Description Phase Votes Comments Actions
530  CVE-1999-0533  Candidate  A DNS server allows inverse queries.  Proposed (19990726)  MODIFY(1) Frech | NOOP(1) Baker | REJECT(1) Northcutt  Northcutt> (rule of thumb) | Frech> XF:dns-iquery  View
215  CVE-1999-0216  Candidate  Denial of service of inetd on Linux through SYN and RST packets.  Modified (19991203-01)  ACCEPT(1) Hill | MODIFY(2) Baker, Frech | RECAST(1) Meunier  Meunier> The location of the vulnerability, whether in the Linux kernel or the | application, is debatable. Any program making the same (reasonnable) | assumption is vulnerable, i.e., implements the same vulnerability: | "Assumption that TCP-three-way handshake is complete after calling Linux | kernel function accept(), which returns socket after getting SYN. Result | is process death by SIGPIPE" | Moreover, whether it results in DOS (to third parties) depends on the | process that made the assumption. | I think that the present entry should be split, one entry for every | application that implements the vulnerability (really describing threat | instances, which is what other people think about when we talk about | vulnerabilities), and one entry for the Linux kernel that allows the | vulnerability to happen. | Frech> XF:hp-inetd | XF:linux-inetd-dos | Baker> Since we have an hpux bulletin, the description should not specifically say Linux, should it? It applies to mulitple OS and should be likely either modified, or in extreme case, recast  View
140  CVE-1999-0140  Candidate  Denial of service in RAS/PPTP on NT systems.  Proposed (19990630)  ACCEPT(1) Hill | MODIFY(2) Frech, Meunier | NOOP(1) Baker | REJECT(1) Christey  Meunier> Add "pptp invalid packet length in header" to distinguish from other | vulnerabilities in RAS/PPTP on NT systems resulting in DOS, that might be | discovered in the future. | Frech> XF:nt-ras-bo | ONLY IF reference is to MS:MS99-016 | Christey> According to my mappings, this is not the MS:MS99-016 problem | referred to by Andre. However, I have yet to dig up a | source. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | CHANGE> [Christey changed vote from REVIEWING to REJECT] | Christey> This is too general to know which problem is being discussed. | More precise candidates should be created. | Christey> Consider adding BID:2111  View
2404  CVE-2000-0835  Candidate  search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.  Modified (20100115)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Collins, Wall | REJECT(2) Baker, Magdych  Magdych> Unless the beta product is in very widespread use, or the product is in | "perpetual beta" (e.g. ICQ), I would prefer not to include beta software. | Christey> XF:sambar-search-view-folder | Frech> XF:sambar-search-view-folder(5247) | Baker> Unless we change our CD:EX-BETA, we should reject this entry. Perhaps we need to address the issue of Beta software again, but the previous discussion was pretty thorough and I believe the editorial board was unanimous in excluding normal beta software. | Christey> Fix typo: "paramater" | Christey> fix typo: "paramatar"  View
3153  CVE-2001-0332  Candidate  Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.  Proposed (20010524)  ACCEPT(4) Baker, Cole, Wall, Ziese | MODIFY(1) Frech | NOOP(1) Renaud | RECAST(1) Williams | REJECT(1) Magdych | REVIEWING(1) Christey  Magdych> Duplicate of CVE-0246 | Christey> While it may look like CVE-2001-0332 is a duplicate of | CVE-2001-0246, Microsoft specifically identifies two separate | variants of the same problem in its advisory, namely 0332 and | 0246. However, CD:SF-LOC currently suggests merging problems | of the same type that appear and are fixed in the same | software versions, and thus these 2 candidates *might* | in fact be duplicates - relative to CD:SF-LOC. Microsoft | needs to be consulted on this. | Williams> merge with CVE-0246 | Frech> XF:ie-frame-verification-read-files(6086) | XF:ie-frame-verification-variant(6748) | CVE-2001-0092 is also assigned to the | ie-frame-verification-files(6086), but shouldn"t be considered a | duplicate.  View

Page 29 of 20943, showing 5 records out of 104715 total, starting on record 141, ending on 145

Actions