CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3144  CVE-2001-0323  Candidate  The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don"t Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.  Modified (20131008)  ACCEPT(2) Frech, Meunier | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop  Christey> (prompted from Pascal Meunier) should this be treated | as a general design issue with ICMP? Or is it a specific | implementation flaw that only affects Reliant? | Meunier> It seems obvious that if one sets the MTU to just one byte | above the size of a IP header (let"s say 21 bytes), data transmission | is not going to go anywhere fast, as the overhead will be 20 times the | payload... As I said for another candidate, ICMP messages should not | be acted upon without access control. I"m not sure that references to | UNIX should be kept. It seems that this should work with any OS. It | would be nasty if some OSes accepted an MTU of 20, as you could not | transmit any IP data.  View
4143  CVE-2001-1339  Candidate  Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.  Modified (20050323)  ACCEPT(2) Frech, Green | NOOP(5) Christey, Cole, Cox, Foat, Wall  Christey> "bas" = "bad"  View
5242  CVE-2002-0852  Candidate  Buffer overflows in Cisco Virtual Private Network (VPN) Client 3.5.4 and earlier allows remote attackers to cause a denial of service via (1) an Internet Key Exchange (IKE) with a large Security Parameter Index (SPI) payload, or (2) an IKE packet with a large number of valid payloads.  Proposed (20020830)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(2) Christey, Cox  Christey> "allows" should be "allow" | Christey> CERT-VN:VU#287771 | URL:http://www.kb.cert.org/vuls/id/287771 | XF:cisco-vpn-spi-bo(9819) | URL:http://www.iss.net/security_center/static/9819.php | XF:cisco-vpn-ike-payload-bo(9820) | URL:http://www.iss.net/security_center/static/9820.php | BID:5441 | URL:http://www.securityfocus.com/bid/5441 | BID:5443 | URL:http://www.securityfocus.com/bid/5443 | Frech> XF:cisco-vpn-spi-bo(9819) | XF:cisco-vpn-ike-payload-bo(9820)  View
1817  CVE-2000-0239  Candidate  Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.  Proposed (20000412)  ACCEPT(3) Baker, Frech, Levy | NOOP(2) Cole, Magdych  CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
1819  CVE-2000-0241  Candidate  vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges.  Proposed (20000412)  ACCEPT(3) Baker, Frech, Levy | NOOP(2) Cole, Magdych  CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View

Page 342 of 20943, showing 5 records out of 104715 total, starting on record 1706, ending on 1710

Actions