CVE List

Id CVE No. Status Description Phase Votes Comments Actions
533  CVE-1999-0537  Candidate  A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.  Proposed (19990726)  ACCEPT(1) Wall | NOOP(1) Baker | RECAST(1) Frech | REJECT(1) LeBlanc  Frech> Good candidate for dot notation. | XF:nav-java-enabled | XF:nav-javascript-enabled | XF:ie-active-content | XF:ie-active-download | XF:ie-active-scripting | XF:ie-activex-execution | XF:ie-java-enabled | XF:netscape-javascript | XF:netscape-java | XF:zone-active-scripting | XF:zone-activex-execution | XF:zone-desktop-install | XF:zone-low-channel | XF:zone-file-download | XF:zone-file-launch | XF:zone-java-scripting | XF:zone-low-java | XF:zone-safe-scripting | XF:zone-unsafe-scripting | LeBlanc> Not a vulnerability. These are just checks for configuration | settings that a user might have changed. I understand need to increase | number of checks in a scanning product, but don"t feel like these belong | in CVE. Scanner vendors could argue that these entries are needed to | keep a common language. | Baker> Not sure about whether we should bother to include this type issue or not. It does provide a stepping stone for further actions, but in and of itself it isn"t a specific vulnerability.  View
540  CVE-1999-0550  Candidate  A router"s routing tables can be obtained from arbitrary hosts.  Proposed (19990726)  ACCEPT(1) Baker | MODIFY(1) Frech | RECAST(1) Northcutt  Northcutt> Don"t you mean obtained by arbitrary hosts | Frech> XF:routed | XF:decod-rip-entry | XF:rip | Baker> Concur with this as a security issue  View
570  CVE-1999-0588  Candidate  A filter in a router or firewall allows unusual fragmented packets.  Proposed (19990726)  MODIFY(2) Baker, Frech | REJECT(1) Northcutt  Northcutt> I want to vote to accept this one, but unusual is a shade broad. | Frech> XF:nt-rras | XF:cisco-fragmented-attacks | XF:ip-frag | Baker> Perhaps we should use the word abnormally fragmented or some other descriptor.  View
580  CVE-1999-0598  Candidate  A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.  Proposed (19990726)  ACCEPT(3) Armstrong, Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey  Frech> Waiting for CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html  View
581  CVE-1999-0599  Candidate  A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.  Proposed (19990726)  ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey  Frech> Waiting for CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html  View

Page 412 of 20943, showing 5 records out of 104715 total, starting on record 2056, ending on 2060

Actions