CVE List

Id CVE No. Status Description Phase Votes Comments Actions
553  CVE-1999-0569  Candidate  A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.  Modified (19991130-01)  ACCEPT(1) Wall | NOOP(2) Baker, Christey | REJECT(1) Northcutt  Northcutt> I do this intentionally somethings in high content directories | Christey> XF:http-noindex(90) ?  View
195  CVE-1999-0195  Candidate  Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.  Modified (19991130-01)  ACCEPT(2) Balinsky, Shostack | MODIFY(1) Frech | NOOP(3) Baker, Northcutt, Wall | REVIEWING(2) Christey, Levy  Frech> XF:rpcbind-spoof | Christey> CVE-1999-0195 = CVE-1999-0461 ? | If this is approved over CVE-1999-0461, make sure it gets | XF:pmap-sset  View
199  CVE-1999-0200  Candidate  Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.  Modified (19991130-01)  ACCEPT(1) Baker | MODIFY(2) Frech, Shostack | NOOP(2) Northcutt, Wall | REJECT(1) Christey | REVIEWING(1) Levy  Shostack> WFTP is not sufficient; is this wu-, ws-, war-, or another? | Frech> Other have mentioned this before, but it may be WU-FTP. | POSSIBLY XF:ftp-exec; does this have to do with the Site Exec allowing root | access without anon FTP or a regular account? | POSSIBLY XF:wu-ftpd-exec;same as above conditions, but instead from a | non-anon FTP account and gain root privs. | Christey> added MSKB reference | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> The MSKB article may have confused things even more. There | were reports of problems in a Windows-based FTP server called | WFTP (http://www.wftpd.com/) that is not a Microsft FTP | server. It"s best to just kill this candidate where it | stands and start fresh.  View
270  CVE-1999-0271  Candidate  Progressive Networks Real Video server (pnserver) can be crashed remotely.  Modified (19990925-01)  ACCEPT(3) Baker, Blake, Northcutt | MODIFY(1) Frech | NOOP(1) Prosser | REVIEWING(1) Christey  Christey> Problem confirmed by RealServer vendor (URL listed in Bugtraq | posting), but may be multiple codebases since several | Real Audio servers are affected. | | Also, this may be the same as BUGTRAQ:19991105 RealNetworks RealServer G2 buffer overflow. | See CVE-1999-0896 | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> ADDREF XF:realvideo-telnet-dos  View
76  CVE-1999-0076  Candidate  Buffer overflow in wu-ftp from PASV command causes a core dump.  Modified (19990925-01)  ACCEPT(3) Baker, Frech, Ozancin | NOOP(1) Balinsky | REVIEWING(1) Christey  Balinsky> Don"t know what this is. Is this the LIST Core dump vulnerability? | Christey> Need to add more references and details.  View

Page 575 of 20943, showing 5 records out of 104715 total, starting on record 2871, ending on 2875

Actions