CVE List

Id CVE No. Status Description Phase Votes Comments Actions
526  CVE-1999-0529  Candidate  A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.  Proposed (19990726)  ACCEPT(1) Frech | MODIFY(2) Baker, Meunier | REJECT(1) Northcutt  Northcutt> I have seen ISPs "assign" private addresses within their domain | Meunier> A border router or firewall forwards packets that claim to come from IANA | reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, | etc, outside of their area of validity. | CHANGE> [Frech changed vote from REVIEWING to ACCEPT] | Baker> I think the description should be modified to say they accept this type of traffic from an interface not residing on private/reserved network.  View
457  CVE-1999-0459  Candidate  Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.  Proposed (19990728)  ACCEPT(1) Frech | NOOP(2) Baker, Northcutt | REJECT(1) Wall  Wall> Reject based on beta copy.  View
2992  CVE-2001-0171  Candidate  Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.  Proposed (20010309)  ACCEPT(1) Frech | NOOP(2) Christey, Ziese | REVIEWING(1) Lawler  Christey> Apparently, the original discoverer re-posted an advisory | saying that version 1.1 was also affected (everything else is | a carbon copy of the original post, so it took me a minute to | see what the deal was :-) | BUGTRAQ:20010228 DOS Vulnerability in SlimServe HTTPd | URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0509.html  View
1047  CVE-1999-1067  Candidate  SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(2) Cole, Foat  Frech> I"d be a lot more confident in this vote if there was a more | concrete reference strongly associating webdist.cgi and machineinfo.  View
1071  CVE-1999-1091  Candidate  UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(2) Cole, Foat    View

Page 672 of 20943, showing 5 records out of 104715 total, starting on record 3356, ending on 3360

Actions