CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
582 | CVE-1999-0600 | Candidate | A network intrusion detection system (IDS) does not verify the checksum on a packet. | Proposed (19990726) | ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey | Frech> Waiting for CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html | View |
583 | CVE-1999-0601 | Candidate | A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets. | Proposed (19990726) | ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey | Frech> Waiting for Godot, er, CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html | View |
584 | CVE-1999-0602 | Candidate | A network intrusion detection system (IDS) does not properly reassemble fragmented packets. | Proposed (19990726) | ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey | Frech> Waiting for CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html | View |
98 | CVE-1999-0098 | Candidate | Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities. | Proposed (19990726) | MODIFY(2) Baker, Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> (Accept XF reference.) | Our references do not mention hiding activities. This issue can crash the | SMTP server or execute arbitrary byte-code. Is there another reference | available? | Christey> Should this be merged with CVE-1999-0284, which is Sendmail | with SMTP HELO? | Christey> BUGTRAQ:19980522 about sendmail 8.8.8 HELO hole | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925991&w=2 | BUGTRAQ:19980527 about sendmail 8.8.8 HELO hole | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101926003&w=2 | Baker> Apparently this XF reference is not for this issue, but for the other issue. This should be modified to have the Bugtraq references, and remove the XF reference. | View |
105 | CVE-1999-0105 | Candidate | finger allows recursive searches by using a long string of @ symbols. | Proposed (19990726) | MODIFY(3) Baker, Frech, Shostack | NOOP(1) Christey | REJECT(1) Northcutt | Shostack> fingerD | Frech> XF:finger-bomb | Christey> aka redirection or forwarding requests? (but then might | overlap CVE-1999-0106) | Baker> should change description to indicate the recursive searching can consume enough system resources to cause a DoS. | View |
Page 413 of 20943, showing 5 records out of 104715 total, starting on record 2061, ending on 2065