CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1234  CVE-1999-1254  Candidate  Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.  Proposed (20010912)  ACCEPT(3) Cole, Frech, Wall | MODIFY(1) Meunier | NOOP(2) Christey, Foat  Christey> Need to get feedback from MS on this. | Christey> (prompted from Pascal Meunier) should this be treated | as a general design issue with ICMP? Or is it a specific | implementation flaw that only affects Reliant? | Meunier> The description is too narrow and incorrect. Spoofed ICMP | redirect messages can be used to setup man-in-the-middle attacks | instead of a DoS. There"s no reason that this behavior would be | limited to Windows, as it is specified by the standard. As I said | elsewhere, ICMP messages should not be acted upon without access | controls.  View
1271  CVE-1999-1291  Candidate  TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target"s last sequence number from the resulting packet, then spoofing a reset to the target.  Proposed (20010912)  ACCEPT(3) Cole, Frech, Wall | NOOP(2) Christey, Foat  Christey> Need to get feedback from MS on this.  View
4431  CVE-2002-0037  Candidate  Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document"s object via a Notes API call (NSFDbReadObject) that directly accesses the object.  Modified (20050528)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cox, Foat  Christey> Need to find some references for these... probably in | the CERT/CC vulnerability notes. | Frech> XF:lotus-domino-nsfdbreadobject(10095) | http://www.kb.cert.org/vuls/id/657899 | CONFIRM: | http://www-1.ibm.com/support/docview.wss?rs=1&org=sims&doc=CCA46CF459B | A6E4A85256AE3007C92C1 | Christey> Is this the same issue here? | BUGTRAQ:20011217 Lotus Notes: File attachments may be extracted regardless of document security | URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0147.html  View
4115  CVE-2001-1311  Candidate  Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.  Modified (20071129)  ACCEPT(5) Cole, Foat, Frech, Green, Wall | NOOP(1) Cox | REVIEWING(1) Christey  Christey> Need to decide if regression errors should get their own CVE"s | or not. A regression error was introduced as explained in: | | VULNWATCH:20030313 R7-0012: Lotus Notes/Domino R6-beta PROTOS LDAP Denial of Service Regression | URL:http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0127.html | | This affects Domino R5.0.7 and earlier, and R6 pre-release/beta  View
963  CVE-1999-0983  Candidate  Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.  Proposed (19991214)  ACCEPT(3) Blake, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Christey  Christey> More examination is required to determine if CVE-1999-0983, | CVE-1999-0984, or CVE-1999-0985 are the same codebase. | Frech> XF:whois-internic-shell-meta | Christey> ADDREF BID:2000 | Christey> The XF appears to be gone. Perhaps it"s this one: | XF:http-cgi-whois-meta(3798)  View

Page 297 of 20943, showing 5 records out of 104715 total, starting on record 1481, ending on 1485

Actions