CVE List

Id CVE No. Status Description Phase Votes Comments Actions
484  CVE-1999-0486  Candidate  Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.  Modified (20000106-01)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:aol-im. | Christey> XF:aol-im appears to be related to the problem discussed in | BUGTRAQ:19980224 AOL Instant Messanger Bug | | This one is related to BUGTRAQ:19990420 AOL Instant Messenger URL Crash  View
1679  CVE-2000-0101  Candidate  The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.  Proposed (20000208)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey | RECAST(1) Cole | REVIEWING(1) Wall  Cole> I would combine all of these shopping cart applications into one listing, | since they all have the same vulnerability being able to modify sensitive | purchase information via hidden form fields. My concern is in cases like | this we used over 10 entries for basically the same vulnerability. I could | think of cases were there could be 20+ applications with the same | vulnerability and in my opinion it could start to weaken the value of CVE | where there are 30 entries all referring to the same thing. It is almost | like we are playing the vendor game where more is better. I think we | should go after the quality over quantity aspect. | Christey> I disagree with Eric here. This vulnerability is a "type" of | problem in the same way that a buffer overflow is a "type" of | problem. While the shopping cart application bugs were | proposed mostly at the same time, they are all by different | vendors. | | The raw numbers of applications with this problem can make it | appear that CVE is artificially inflating the number of | entries. However, content decisions such as CD:SF-LOC | (different lines of code) dictate that these should be | separated. It"s not a "numbers game" but rather a principled | and consistent approach to resolving problems with | selecting a level of abstraction. | Frech> XF:shopping-cart-form-tampering  View
764  CVE-1999-0784  Candidate  Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.  Proposed (20010214)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Cole  Frech> XF:oracle-tnslsnr-dos(1551)  View
2696  CVE-2000-1129  Candidate  McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Wall  Frech> XF:webshield-smtp-recpt-dos(5572)  View
634  CVE-1999-0652  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A database service is running, e.g. a SQL server, Oracle, or mySQL."  Modified (20080731)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Wall | REJECT(1) Northcutt  Frech> XF:nt-sql-server(1289) | XF:msql-detect(2211) | XF:oracle-detect(2388) | XF:sybase-detect-namedpipes(1461)  View

Page 618 of 20943, showing 5 records out of 104715 total, starting on record 3086, ending on 3090

Actions