CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1208  CVE-1999-1228  Candidate  Various modems that do not implement a guard time, or are configured with a guard time of 0, can allow remote attackers to execute arbitrary modem commands such as ATH, ATH0, etc., via a "+++" sequence that appears in ICMP packets, the subject of an e-mail message, IRC commands, and others.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
3477  CVE-2001-0669  Candidate  Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.  Modified (20050510)  ACCEPT(4) Armstrong, Baker, Balinsky, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:iis-unicode-encoding-detected(6994) | XF:iis-unicode-wide-encoding(6995)  View
7570  CVE-2003-0746  Candidate  Various Distributed Computing Environment (DCE) implementations, including HP OpenView, allow remote attackers to cause a denial of service (process hang or termination) via certain malformed inputs, as triggered by attempted exploits against the vulnerabilities CVE-2003-0352 or CVE-2003-0605, such as the Blaster/MSblast/LovSAN worm.  Assigned (20030904)  None (candidate not yet proposed)    View
2295  CVE-2000-0719  Candidate  VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.  Proposed (20000921)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Williams | REVIEWING(1) Levy  Christey> XF:varicad-world-write-permissions | http://xforce.iss.net/static/5077.php | Frech> XF:aricad-world-write-permissions(5077) | Christey> BID:1862  View
2671  CVE-2000-1104  Candidate  Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.  Proposed (20001219)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech  Frech> XF:iis-cross-site-scripting(5156)  View

Page 570 of 20943, showing 5 records out of 104715 total, starting on record 2846, ending on 2850

Actions