CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2755 | CVE-2000-1188 | Candidate | Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter. | Modified (20060413) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall | Frech> XF:quikstore-cgi-read-files(5561) | Armstrong> in Description: change rmeote to remote. | View |
1381 | CVE-1999-1401 | Candidate | Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook). | Modified (20060309) | ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | Frech> XF:irix-searchbook-permissions(7575) | View |
617 | CVE-1999-0635 | Candidate | The echo service is running. | Modified (20060122) | ACCEPT(3) Baker, Northcutt, Wall | REVIEWING(1) Christey | Northcutt> The method to my madness is echo is the common denom in the dos attack | Christey> How much of this is an overlap with the echo/chargen flood | problem (CVE-1999-0103)? If this is only an exposure because | of CVE-1999-0103, then maybe this should be REJECTed. | View |
5576 | CVE-2002-1192 | Candidate | Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file. | Modified (20051218) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | View | |
1 | CVE-1999-0001 | Candidate | ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. | Modified (20051217) | MODIFY(1) Frech | NOOP(2) Northcutt, Wall | REVIEWING(1) Christey | Christey> A Bugtraq posting indicates that the bug has to do with | "short packets with certain options set," so the description | should be modified accordingly. | | But is this the same as CVE-1999-0052? That one is related | to nestea (CVE-1999-0257) and probably the one described in | BUGTRAQ:19981023 nestea v2 against freebsd 3.0-Release | The patch for nestea is in ip_input.c around line 750. | The patches for CVE-1999-0001 are in lines 388&446. So, | CVE-1999-0001 is different from CVE-1999-0257 and CVE-1999-0052. | The FreeBSD patch for CVE-1999-0052 is in line 750. | So, CVE-1999-0257 and CVE-1999-0052 may be the same, though | CVE-1999-0052 should be RECAST since this bug affects Linux | and other OSes besides FreeBSD. | Frech> XF:teardrop(338) | This assignment was based solely on references to the CERT advisory. | Christey> The description for BID:190, which links to CVE-1999-0052 (a | FreeBSD advisory), notes that the patches provided by FreeBSD in | CERT:CA-1998-13 suggest a connection between CVE-1999-0001 and | CVE-1999-0052. CERT:CA-1998-13 is too vague to be sure without | further analysis. | View |
Page 491 of 20943, showing 5 records out of 104715 total, starting on record 2451, ending on 2455