CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3149  CVE-2001-0328  Candidate  TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.  Modified (20161125)  ACCEPT(7) Baker, Cole, Magdych, Renaud, Wall, Williams, Ziese | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:tcp-seq-predict(139) | Christey> It could be argued that this is a "class" of vulnerability in which | several stacks have the problem. | Also need to add references. | Christey> Consider adding BID:2682 | Christey> HP:HPSBUX0207-205 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0031.html | Christey> COMPAQ:SSRT-547 | URL:http://archives.neohapsis.com/archives/tru64/2002-q3/0017.html | HP:HPSBUX0207-205 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0031.html  View
2485  CVE-2000-0916  Candidate  FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.  Proposed (20001129)  ACCEPT(2) Cole, Mell | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:tcp-seq-predict(139) | Christey> Abstraction issue: CVE-1999-0077 is for TCP sequence | prediction as a general problem; but here we have a specific | implementation flaw.  View
4688  CVE-2002-0296  Candidate  The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.  Modified (20050527)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:tarantella-tmp-spinning-symlink(8223)  View
3238  CVE-2001-0420  Candidate  Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:talkback-cgi-read-files(6340) | Christey> BID:2547 | URL:http://www.securityfocus.com/bid/2547  View
1186  CVE-1999-1206  Candidate  SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.  Proposed (20010912)  ACCEPT(4) Armstrong, Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:systemwizard-modify-registry(7080) | Christey> CERT-VN:VU#22919 | URL:http://www.kb.cert.org/vuls/id/22919 | CERT-VN:VU#34453 | URL:http://www.kb.cert.org/vuls/id/34453  View

Page 72 of 20943, showing 5 records out of 104715 total, starting on record 356, ending on 360

Actions