CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
400 | CVE-1999-0401 | Candidate | A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files. | Modified (20000105-01) | ACCEPT(1) Baker | MODIFY(1) Frech | Frech> XF:linux-race-condition-proc | View |
418 | CVE-1999-0419 | Candidate | When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service. | Modified (20000105-01) | ACCEPT(1) Baker | MODIFY(2) Frech, LeBlanc | REVIEWING(1) Christey | Frech> XF:smtp-4xx-error-dos | LeBlanc> - if we can find a KB or something that shows that this wasn"t just | user error, I"d vote ACCEPT. | Christey> David Lemson, Microsoft SMTP Service Program Manager, | posted a followup that said "We have confirmed this as a | problem..." | http://marc.theaimsgroup.com/?l=bugtraq&m=92171608127206&w=2 | View |
228 | CVE-1999-0229 | Candidate | Denial of service in Windows NT IIS server using .... | Modified (19991228-02) | ACCEPT(2) Baker, Shostack | MODIFY(2) Frech, Wall | NOOP(1) Northcutt | REJECT(1) Christey | REVIEWING(1) Levy | Wall> Denial of service in Windows NT IIS Server 1.0 using ..... | Source: Microsoft Knowledge Base Article Q115052 - IIS Server. | Frech> XF:http-dotdot (not necessarily IIS?) | Christey> DELREF XF:http-dotdot - it deals with a read/access dot dot | problem. | Christey> This actually looks like XF:iis-dot-dot-crash(1638) | http://xforce.iss.net/static/1638.php | If so, include the version number (2.0) | | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> Bill Wall intended to suggest Q155052, but the affected | IIS version there is 1.0; the effect is to read files, | so this sounds like a directory traversal problem, | instead of an inability to process certain strings. | | As a result, this candidate is too general, since it could | apply to 2 different problems, so it should be REJECTed. | Christey> Consider adding BID:2218 | View |
658 | CVE-1999-0677 | Candidate | The WebRamp web administration utility has a default password. | Modified (19991228-01) | ACCEPT(3) Baker, Blake, Stracener | MODIFY(2) Cole, Frech | NOOP(2) Armstrong, Christey | Cole> I would add that is is not forced to be changed. | Frech> XF:webramp-default-password | Christey> This problem may have been detected in January 1999: | BUGTRAQ:19990121 Re: WebRamp M3 remote network access bug | http://marc.theaimsgroup.com/?l=bugtraq&m=91702375402055&w=2 | View |
107 | CVE-1999-0107 | Candidate | Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters. | Modified (19991223-01) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Northcutt, Shostack, Wall | REVIEWING(1) Levy | REVOTE(1) Christey | Wall> - Although this is probably the phf hack. | Frech> XF:apache-dos | Christey> This sounds like the incident reported in: | NTBUGTRAQ:20000810 Apache Distributed Denial of Service | Levy> I belive this is the problem where sending lot of HTTP headers to apache resulted on a denial of service. | BUGTRAQ: http://www.securityfocus.com/archive/1/10228 | BUGTRAQ: http://www.securityfocus.com/archive/1/10516 | View |
Page 571 of 20943, showing 5 records out of 104715 total, starting on record 2851, ending on 2855