CVE List

Id CVE No. Status Description Phase Votes Comments Actions
983  CVE-1999-1003  Candidate  War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.  Proposed (19991222)  ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:warftp-connection-flood  View
730  CVE-1999-0750  Candidate  Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user"s Hotmail account.  Proposed (19991222)  ACCEPT(1) Levy | MODIFY(2) Frech, Stracener | NOOP(1) Baker  Stracener> Many sites are vulnerable to this problem. I recommend removing the | explicit references to Hotmail and making the description more generic. | Suggest: Javascript can be injected using the STYLE tag in an HTML | formatted e-mail, allowing remote attackers to execute commands on user | accounts. | Frech> XF:hotmail-html-style-embed  View
986  CVE-1999-1006  Candidate  Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.  Proposed (19991222)  ACCEPT(4) Baker, Cole, Prosser, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:groupwise-web-path | Prosser> Pretty well confirmed by testing with responses to BugTraq list. | | additional ref: BugTraq ID 879 http://www.securityfocus.com/bid/879 | Christey> A later discovery almost 2 years later is at: | BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell | GroupWise Web Access Path Disclosure Vulnerability | http://marc.theaimsgroup.com/?l=bugtraq&m=101494830315071&w=2 | CD:SF-LOC might suggest merging these together.  View
989  CVE-1999-1009  Candidate  The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user"s system.  Proposed (19991222)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Balinsky, Cole, Stracener, Wall  Frech> XF:disney-search-info(3955) | Balinsky> The go.express.com web site does not mention the existence of the Express web server mentioned in the advisory. There appears to be no way of verifying this.  View
852  CVE-1999-0872  Candidate  Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.  Proposed (19991214)  MODIFY(2) Cole, Frech | NOOP(1) Baker | REJECT(3) Blake, Christey, Stracener  Cole> 611 is the mail to listed above but 759 is for the mail from and | should be listed as a separate vulenrability. | Blake> This does not appear materially different from CVE-1999-0768 | Christey> This is an apparent duplicate of CVE-1999-0768. | REDHAT:RHSA-1999:030-02 describes two issues, one of which is | CVE-1999-0768, and the other is CVE-1999-0769. | Stracener> This is a duplicate of candidate CVE-1999-0768. | Frech> XF:cron-sendmail-bo-root | Christey> BID:759 is improperly assigned to this candidate and doesn"t | even describe it. It may have been inadvertently copied | from CVE-1999-0873.  View

Page 388 of 20943, showing 5 records out of 104715 total, starting on record 1936, ending on 1940

Actions