CVE List

Id CVE No. Status Description Phase Votes Comments Actions
862  CVE-1999-0882  Candidate  Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.  Proposed (19991214)  ACCEPT(3) Baker, Blake, Stracener | MODIFY(1) Frech | NOOP(2) Armstrong, Cole  Frech> XF:falcon-server-long-filename  View
893  CVE-1999-0913  Candidate  dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.  Proposed (19991214)  ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(4) Armstrong, Baker, Cole, LeBlanc | REVIEWING(1) Christey  Christey> Some voters should use ABSTAIN. | Frech> XF:dragon-fire-ids-metachar(3834) | CHANGE> [Armstrong changed vote from REVIEWING to NOOP]  View
665  CVE-1999-0684  Candidate  Denial of service in Sendmail 8.8.6 in HPUX.  Proposed (19991214)  ACCEPT(2) Blake, Cole | MODIFY(3) Frech, Prosser, Stracener | NOOP(1) Baker | REJECT(1) Christey  Stracener> Add Ref: CIAC: J-040 | Prosser> Might change description to indicate DoS caused by multiple connections | Christey> Andre"s right. This is a duplicate of CVE-1999-0684. | Frech> Without further information and/or references, this issue looks like an | ambiguous version of CVE-1999-0478: Denial of service in HP-UX sendmail | 8.8.6 related to accepting connections. | | (was REJECT) | XF:hp-sendmail-connect-dos  View
692  CVE-1999-0712  Candidate  A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.  Proposed (19991214)  ACCEPT(4) Baker, Cole, Frech, Stracener | MODIFY(1) Blake | NOOP(1) Armstrong | REVIEWING(1) Christey  Blake> This obscurely-written advisory seems to state that COAS will make the | file world-readable, not that it allows the user to make it so. I hardly | think that allowing the user to turn off security is a vulnerability. | Christey> It"s difficult to write the description based on what"s in | the advisory. If COAS inadvertently changes permissions | without user confirmation, then it should be ACCEPTed with | appropriate modification to the description. | Christey> ADDREF BID:137 | CHANGE> [Armstrong changed vote from REVIEWING to NOOP]  View
963  CVE-1999-0983  Candidate  Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.  Proposed (19991214)  ACCEPT(3) Blake, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Christey  Christey> More examination is required to determine if CVE-1999-0983, | CVE-1999-0984, or CVE-1999-0985 are the same codebase. | Frech> XF:whois-internic-shell-meta | Christey> ADDREF BID:2000 | Christey> The XF appears to be gone. Perhaps it"s this one: | XF:http-cgi-whois-meta(3798)  View

Page 389 of 20943, showing 5 records out of 104715 total, starting on record 1941, ending on 1945

Actions