CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
526 | CVE-1999-0529 | Candidate | A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc. | Proposed (19990726) | ACCEPT(1) Frech | MODIFY(2) Baker, Meunier | REJECT(1) Northcutt | Northcutt> I have seen ISPs "assign" private addresses within their domain | Meunier> A border router or firewall forwards packets that claim to come from IANA | reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, | etc, outside of their area of validity. | CHANGE> [Frech changed vote from REVIEWING to ACCEPT] | Baker> I think the description should be modified to say they accept this type of traffic from an interface not residing on private/reserved network. | View |
457 | CVE-1999-0459 | Candidate | Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot. | Proposed (19990728) | ACCEPT(1) Frech | NOOP(2) Baker, Northcutt | REJECT(1) Wall | Wall> Reject based on beta copy. | View |
2992 | CVE-2001-0171 | Candidate | Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request. | Proposed (20010309) | ACCEPT(1) Frech | NOOP(2) Christey, Ziese | REVIEWING(1) Lawler | Christey> Apparently, the original discoverer re-posted an advisory | saying that version 1.1 was also affected (everything else is | a carbon copy of the original post, so it took me a minute to | see what the deal was :-) | BUGTRAQ:20010228 DOS Vulnerability in SlimServe HTTPd | URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0509.html | View |
1047 | CVE-1999-1067 | Candidate | SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(2) Cole, Foat | Frech> I"d be a lot more confident in this vote if there was a more | concrete reference strongly associating webdist.cgi and machineinfo. | View |
1071 | CVE-1999-1091 | Candidate | UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(2) Cole, Foat | View |
Page 672 of 20943, showing 5 records out of 104715 total, starting on record 3356, ending on 3360