CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2755  CVE-2000-1188  Candidate  Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.  Modified (20060413)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:quikstore-cgi-read-files(5561) | Armstrong> in Description: change rmeote to remote.  View
1381  CVE-1999-1401  Candidate  Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).  Modified (20060309)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech  Frech> XF:irix-searchbook-permissions(7575)  View
617  CVE-1999-0635  Candidate  The echo service is running.  Modified (20060122)  ACCEPT(3) Baker, Northcutt, Wall | REVIEWING(1) Christey  Northcutt> The method to my madness is echo is the common denom in the dos attack | Christey> How much of this is an overlap with the echo/chargen flood | problem (CVE-1999-0103)? If this is only an exposure because | of CVE-1999-0103, then maybe this should be REJECTed.  View
5576  CVE-2002-1192  Candidate  Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.  Modified (20051218)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
CVE-1999-0001  Candidate  ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.  Modified (20051217)  MODIFY(1) Frech | NOOP(2) Northcutt, Wall | REVIEWING(1) Christey  Christey> A Bugtraq posting indicates that the bug has to do with | "short packets with certain options set," so the description | should be modified accordingly. | | But is this the same as CVE-1999-0052? That one is related | to nestea (CVE-1999-0257) and probably the one described in | BUGTRAQ:19981023 nestea v2 against freebsd 3.0-Release | The patch for nestea is in ip_input.c around line 750. | The patches for CVE-1999-0001 are in lines 388&446. So, | CVE-1999-0001 is different from CVE-1999-0257 and CVE-1999-0052. | The FreeBSD patch for CVE-1999-0052 is in line 750. | So, CVE-1999-0257 and CVE-1999-0052 may be the same, though | CVE-1999-0052 should be RECAST since this bug affects Linux | and other OSes besides FreeBSD. | Frech> XF:teardrop(338) | This assignment was based solely on references to the CERT advisory. | Christey> The description for BID:190, which links to CVE-1999-0052 (a | FreeBSD advisory), notes that the patches provided by FreeBSD in | CERT:CA-1998-13 suggest a connection between CVE-1999-0001 and | CVE-1999-0052. CERT:CA-1998-13 is too vague to be sure without | further analysis.  View

Page 491 of 20943, showing 5 records out of 104715 total, starting on record 2451, ending on 2455

Actions