CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
983 | CVE-1999-1003 | Candidate | War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections. | Proposed (19991222) | ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:warftp-connection-flood | View |
730 | CVE-1999-0750 | Candidate | Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user"s Hotmail account. | Proposed (19991222) | ACCEPT(1) Levy | MODIFY(2) Frech, Stracener | NOOP(1) Baker | Stracener> Many sites are vulnerable to this problem. I recommend removing the | explicit references to Hotmail and making the description more generic. | Suggest: Javascript can be injected using the STYLE tag in an HTML | formatted e-mail, allowing remote attackers to execute commands on user | accounts. | Frech> XF:hotmail-html-style-embed | View |
986 | CVE-1999-1006 | Candidate | Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter. | Proposed (19991222) | ACCEPT(4) Baker, Cole, Prosser, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:groupwise-web-path | Prosser> Pretty well confirmed by testing with responses to BugTraq list. | | additional ref: BugTraq ID 879 http://www.securityfocus.com/bid/879 | Christey> A later discovery almost 2 years later is at: | BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell | GroupWise Web Access Path Disclosure Vulnerability | http://marc.theaimsgroup.com/?l=bugtraq&m=101494830315071&w=2 | CD:SF-LOC might suggest merging these together. | View |
989 | CVE-1999-1009 | Candidate | The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user"s system. | Proposed (19991222) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Balinsky, Cole, Stracener, Wall | Frech> XF:disney-search-info(3955) | Balinsky> The go.express.com web site does not mention the existence of the Express web server mentioned in the advisory. There appears to be no way of verifying this. | View |
852 | CVE-1999-0872 | Candidate | Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. | Proposed (19991214) | MODIFY(2) Cole, Frech | NOOP(1) Baker | REJECT(3) Blake, Christey, Stracener | Cole> 611 is the mail to listed above but 759 is for the mail from and | should be listed as a separate vulenrability. | Blake> This does not appear materially different from CVE-1999-0768 | Christey> This is an apparent duplicate of CVE-1999-0768. | REDHAT:RHSA-1999:030-02 describes two issues, one of which is | CVE-1999-0768, and the other is CVE-1999-0769. | Stracener> This is a duplicate of candidate CVE-1999-0768. | Frech> XF:cron-sendmail-bo-root | Christey> BID:759 is improperly assigned to this candidate and doesn"t | even describe it. It may have been inadvertently copied | from CVE-1999-0873. | View |
Page 388 of 20943, showing 5 records out of 104715 total, starting on record 1936, ending on 1940