CVE List

Id CVE No. Status Description Phase Votes Comments Actions
400  CVE-1999-0401  Candidate  A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.  Modified (20000105-01)  ACCEPT(1) Baker | MODIFY(1) Frech  Frech> XF:linux-race-condition-proc  View
418  CVE-1999-0419  Candidate  When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.  Modified (20000105-01)  ACCEPT(1) Baker | MODIFY(2) Frech, LeBlanc | REVIEWING(1) Christey  Frech> XF:smtp-4xx-error-dos | LeBlanc> - if we can find a KB or something that shows that this wasn"t just | user error, I"d vote ACCEPT. | Christey> David Lemson, Microsoft SMTP Service Program Manager, | posted a followup that said "We have confirmed this as a | problem..." | http://marc.theaimsgroup.com/?l=bugtraq&m=92171608127206&w=2  View
228  CVE-1999-0229  Candidate  Denial of service in Windows NT IIS server using ....  Modified (19991228-02)  ACCEPT(2) Baker, Shostack | MODIFY(2) Frech, Wall | NOOP(1) Northcutt | REJECT(1) Christey | REVIEWING(1) Levy  Wall> Denial of service in Windows NT IIS Server 1.0 using ..... | Source: Microsoft Knowledge Base Article Q115052 - IIS Server. | Frech> XF:http-dotdot (not necessarily IIS?) | Christey> DELREF XF:http-dotdot - it deals with a read/access dot dot | problem. | Christey> This actually looks like XF:iis-dot-dot-crash(1638) | http://xforce.iss.net/static/1638.php | If so, include the version number (2.0) | | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> Bill Wall intended to suggest Q155052, but the affected | IIS version there is 1.0; the effect is to read files, | so this sounds like a directory traversal problem, | instead of an inability to process certain strings. | | As a result, this candidate is too general, since it could | apply to 2 different problems, so it should be REJECTed. | Christey> Consider adding BID:2218  View
658  CVE-1999-0677  Candidate  The WebRamp web administration utility has a default password.  Modified (19991228-01)  ACCEPT(3) Baker, Blake, Stracener | MODIFY(2) Cole, Frech | NOOP(2) Armstrong, Christey  Cole> I would add that is is not forced to be changed. | Frech> XF:webramp-default-password | Christey> This problem may have been detected in January 1999: | BUGTRAQ:19990121 Re: WebRamp M3 remote network access bug | http://marc.theaimsgroup.com/?l=bugtraq&m=91702375402055&w=2  View
107  CVE-1999-0107  Candidate  Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.  Modified (19991223-01)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Northcutt, Shostack, Wall | REVIEWING(1) Levy | REVOTE(1) Christey  Wall> - Although this is probably the phf hack. | Frech> XF:apache-dos | Christey> This sounds like the incident reported in: | NTBUGTRAQ:20000810 Apache Distributed Denial of Service | Levy> I belive this is the problem where sending lot of HTTP headers to apache resulted on a denial of service. | BUGTRAQ: http://www.securityfocus.com/archive/1/10228 | BUGTRAQ: http://www.securityfocus.com/archive/1/10516  View

Page 571 of 20943, showing 5 records out of 104715 total, starting on record 2851, ending on 2855

Actions