CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
553 | CVE-1999-0569 | Candidate | A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. | Modified (19991130-01) | ACCEPT(1) Wall | NOOP(2) Baker, Christey | REJECT(1) Northcutt | Northcutt> I do this intentionally somethings in high content directories | Christey> XF:http-noindex(90) ? | View |
195 | CVE-1999-0195 | Candidate | Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. | Modified (19991130-01) | ACCEPT(2) Balinsky, Shostack | MODIFY(1) Frech | NOOP(3) Baker, Northcutt, Wall | REVIEWING(2) Christey, Levy | Frech> XF:rpcbind-spoof | Christey> CVE-1999-0195 = CVE-1999-0461 ? | If this is approved over CVE-1999-0461, make sure it gets | XF:pmap-sset | View |
199 | CVE-1999-0200 | Candidate | Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password. | Modified (19991130-01) | ACCEPT(1) Baker | MODIFY(2) Frech, Shostack | NOOP(2) Northcutt, Wall | REJECT(1) Christey | REVIEWING(1) Levy | Shostack> WFTP is not sufficient; is this wu-, ws-, war-, or another? | Frech> Other have mentioned this before, but it may be WU-FTP. | POSSIBLY XF:ftp-exec; does this have to do with the Site Exec allowing root | access without anon FTP or a regular account? | POSSIBLY XF:wu-ftpd-exec;same as above conditions, but instead from a | non-anon FTP account and gain root privs. | Christey> added MSKB reference | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> The MSKB article may have confused things even more. There | were reports of problems in a Windows-based FTP server called | WFTP (http://www.wftpd.com/) that is not a Microsft FTP | server. It"s best to just kill this candidate where it | stands and start fresh. | View |
270 | CVE-1999-0271 | Candidate | Progressive Networks Real Video server (pnserver) can be crashed remotely. | Modified (19990925-01) | ACCEPT(3) Baker, Blake, Northcutt | MODIFY(1) Frech | NOOP(1) Prosser | REVIEWING(1) Christey | Christey> Problem confirmed by RealServer vendor (URL listed in Bugtraq | posting), but may be multiple codebases since several | Real Audio servers are affected. | | Also, this may be the same as BUGTRAQ:19991105 RealNetworks RealServer G2 buffer overflow. | See CVE-1999-0896 | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> ADDREF XF:realvideo-telnet-dos | View |
76 | CVE-1999-0076 | Candidate | Buffer overflow in wu-ftp from PASV command causes a core dump. | Modified (19990925-01) | ACCEPT(3) Baker, Frech, Ozancin | NOOP(1) Balinsky | REVIEWING(1) Christey | Balinsky> Don"t know what this is. Is this the LIST Core dump vulnerability? | Christey> Need to add more references and details. | View |
Page 575 of 20943, showing 5 records out of 104715 total, starting on record 2871, ending on 2875