CVE List

Id CVE No. Status Description Phase Votes Comments Actions
582  CVE-1999-0600  Candidate  A network intrusion detection system (IDS) does not verify the checksum on a packet.  Proposed (19990726)  ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey  Frech> Waiting for CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html  View
583  CVE-1999-0601  Candidate  A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.  Proposed (19990726)  ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey  Frech> Waiting for Godot, er, CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html  View
584  CVE-1999-0602  Candidate  A network intrusion detection system (IDS) does not properly reassemble fragmented packets.  Proposed (19990726)  ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey  Frech> Waiting for CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html  View
98  CVE-1999-0098  Candidate  Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.  Proposed (19990726)  MODIFY(2) Baker, Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> (Accept XF reference.) | Our references do not mention hiding activities. This issue can crash the | SMTP server or execute arbitrary byte-code. Is there another reference | available? | Christey> Should this be merged with CVE-1999-0284, which is Sendmail | with SMTP HELO? | Christey> BUGTRAQ:19980522 about sendmail 8.8.8 HELO hole | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925991&w=2 | BUGTRAQ:19980527 about sendmail 8.8.8 HELO hole | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101926003&w=2 | Baker> Apparently this XF reference is not for this issue, but for the other issue. This should be modified to have the Bugtraq references, and remove the XF reference.  View
105  CVE-1999-0105  Candidate  finger allows recursive searches by using a long string of @ symbols.  Proposed (19990726)  MODIFY(3) Baker, Frech, Shostack | NOOP(1) Christey | REJECT(1) Northcutt  Shostack> fingerD | Frech> XF:finger-bomb | Christey> aka redirection or forwarding requests? (but then might | overlap CVE-1999-0106) | Baker> should change description to indicate the recursive searching can consume enough system resources to cause a DoS.  View

Page 413 of 20943, showing 5 records out of 104715 total, starting on record 2061, ending on 2065

Actions