CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3149 | CVE-2001-0328 | Candidate | TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN. | Modified (20161125) | ACCEPT(7) Baker, Cole, Magdych, Renaud, Wall, Williams, Ziese | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:tcp-seq-predict(139) | Christey> It could be argued that this is a "class" of vulnerability in which | several stacks have the problem. | Also need to add references. | Christey> Consider adding BID:2682 | Christey> HP:HPSBUX0207-205 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0031.html | Christey> COMPAQ:SSRT-547 | URL:http://archives.neohapsis.com/archives/tru64/2002-q3/0017.html | HP:HPSBUX0207-205 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0031.html | View |
2485 | CVE-2000-0916 | Candidate | FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. | Proposed (20001129) | ACCEPT(2) Cole, Mell | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:tcp-seq-predict(139) | Christey> Abstraction issue: CVE-1999-0077 is for TCP sequence | prediction as a general problem; but here we have a specific | implementation flaw. | View |
4688 | CVE-2002-0296 | Candidate | The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file. | Modified (20050527) | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | Frech> XF:tarantella-tmp-spinning-symlink(8223) | View |
3238 | CVE-2001-0420 | Candidate | Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | Frech> XF:talkback-cgi-read-files(6340) | Christey> BID:2547 | URL:http://www.securityfocus.com/bid/2547 | View |
1186 | CVE-1999-1206 | Candidate | SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control. | Proposed (20010912) | ACCEPT(4) Armstrong, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:systemwizard-modify-registry(7080) | Christey> CERT-VN:VU#22919 | URL:http://www.kb.cert.org/vuls/id/22919 | CERT-VN:VU#34453 | URL:http://www.kb.cert.org/vuls/id/34453 | View |
Page 72 of 20943, showing 5 records out of 104715 total, starting on record 356, ending on 360