CVE List

Id CVE No. Status Description Phase Votes Comments Actions
449  CVE-1999-0450  Candidate  In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).  Modified (20090622)  ACCEPT(2) Ozancin, Wall | NOOP(2) Baker, Christey | REJECT(2) Frech, LeBlanc  Frech> Can"t find in database. | Christey> This looks like another discovery of CVE-2000-0071 | LeBlanc> - I just tried to repro this based on the BUGTRAQ vuln information, | and it does not repro - | GET /bogus.pl HTTP/1.0 | HTTP/1.1 404 Object Not Found | Server: Microsoft-IIS/5.0 | Date: Thu, 05 Oct 2000 21:04:20 GMT | Content-Length: 3243 | Content-Type: text/html | No path is returned whatsoever. This may have been a problem on some version | of IIS in the past, but the BUGTRAQ ID says all versions are vulnerable. | Let"s try and figure out what version had the problem, whether it is | intrinsic to IIS or the result of adding a 3rd party implementation of perl, | and when it got fixed, then we can try again. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Christey> Add "no-such-file.pl" as an example to the desc, to facilitate | search (it"s used by CGI scanners and in the original example)  View
15  CVE-1999-0015  Candidate  Teardrop IP denial of service.  Modified (20090302)  ACCEPT(1) Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF: teardrop-mod | Christey> Not sure how many separate "instances" of Teardrop there are. | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> MSKB:Q154174 | MSKB:Q154174 (CVE-1999-0015) and MSKB:Q179129 (CVE-1999-0104) | indicate that CVE-1999-0015 was fixed in NT SP3, but | CVE-1999-0104 was not. Thus CD:SF-LOC suggests that the | problems keep separate candidates because one problem appears | in a different version than the other. | Christey> BID:124 | http://www.securityfocus.com/bid/124 | Consider MSKB:Q154174 | http://support.microsoft.com/support/kb/articles/q154/1/74.asp | Consider BUGTRAQ:19971113 Linux IP fragment overlap bug | http://www.securityfocus.com/archive/1/8014  View
3615  CVE-2001-0809  Candidate  Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.  Modified (20090302)  ACCEPT(4) Armstrong, Bishop, Cole, Foat | NOOP(1) Wall | REJECT(1) Frech  Frech> See XF:samba-tmpfile-symlink(6396). | Discovery and advisory are two months apart, and no other Samba | issues seem to exist around that timespan.  View
8482  CVE-2004-0054  Candidate  Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.  Modified (20090302)  ACCEPT(5) Armstrong, Baker, Cole, Green, Wall | NOOP(1) Cox    View
3364  CVE-2001-0551  Candidate  Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.  Modified (20090302)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(2) Christey, Green  Christey> There is some overlap between CVE-2001-0551 and CVE-2001-0772. | CVE-2001-0551 describes a specific vulnerability in | dtprintinfo. HP acknowledges CVE-2001-0551 by stating | that the problem is fixed in HP:HPSBUX0105-151, which | is CVE-2001-0772. But CVE-2001-0772 is a vague advisory | that identifies other vulnerabilities (and vulnerability | types) besides CVE-2001-0551. Perhaps CVE-2001-0772 should | be RECAST to "remove" the reference to dtprintinfo and | leave the other vague descriptions. CVE-2001-0772 and | CVE-2001-0551 are very good examples of the problems that | CVE faces in being consistent with respect to the level of | abstraction, as documented in the CD:SF-CODEBASE, CD:SF-LOC, | and CD:VAGUE content decisions. | Baker> We should rewrite the candidate entry CVE-2001-0772 to address the other issues, and point the dtprintinfo issue to this entry. | Frech> XF:cde-dtprintinfo-bo(8034) | Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2406 - CDE dtprintinfo Help sea rch buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0036.html | BID:4630 | URL:http://www.securityfocus.com/bid/4630 | Christey> CALDERA:CSSA-2002-SCO.30 | Christey> COMPAQ:SSRT2405 | URL:http://www.securityfocus.com/advisories/5997 | BID:8888 | URL:http://www.securityfocus.com/bid/8888  View

Page 436 of 20943, showing 5 records out of 104715 total, starting on record 2176, ending on 2180

Actions