CVE List

Id CVE No. Status Description Phase Votes Comments Actions
495  CVE-1999-0497  Candidate  Anonymous FTP is enabled.  Modified (20040811)  ACCEPT(1) Shostack | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Northcutt  Frech> ftp-anon(52) at http://xforce.iss.net/static/52.php | ftp-anon2(543) at http://xforce.iss.net/static/543.php | Christey> Add period to the end of the description. | Baker> DOn"t know about this, but it may be the only easy way to allow access to data for some folks.  View
538  CVE-1999-0548  Candidate  A superfluous NFS server is running, but it is not importing or exporting any file systems.  Proposed (19990728)  ACCEPT(1) Shostack | NOOP(1) Baker | REJECT(1) Northcutt    View
242  CVE-1999-0243  Candidate  Linux cfingerd could be exploited to gain root access.  Proposed (19990714)  ACCEPT(1) Shostack | NOOP(4) Baker, Levy, Northcutt, Wall | REJECT(2) Christey, Frech  Christey> This has no sources; neither does the original database that | this entry came from. It"s a likely duplicate of | CVE-1999-0813. | Frech> I disagree on the dupe; see Linux-Security Mailing List, | "[linux-security] Cfinger (Yet more :)" at | http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as | if v1.2.3 is vulnerable, perhaps 1.3.0 also. CVE-1999-0813 pertains | to 1.4.x and below and shows up two years later. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> If the reference I previously supplied is correct, then | it appears as if the poster modified the source using authorized | access to make it vulnerable. Modifying the source in this manner | does not qualify as being listed a vulnerability. | I disagree on the dupe; see Linux-Security Mailing List, | "[linux-security] Cfinger (Yet more :)" at | http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as | if v1.2.3 is vulnerable, perhaps 1.3.0 also. CVE-1999-0813 pertains | to 1.4.x and below and shows up two years later.  View
2758  CVE-2000-1191  Candidate  htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.  Modified (20100819)  ACCEPT(1) Stracener | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Williams  Frech> XF:htdig-htsearch-path-disclosure(7367) | MISC reference should be | http://www.securiteam.com/exploits/5YQ0C000IU.html.  View
921  CVE-1999-0941  Candidate  Mutt mail client allows a remote attacker to execute commands via shell metacharacters.  Proposed (19991222)  ACCEPT(1) Stracener | NOOP(2) Baker, Christey | REJECT(1) Frech | REVIEWING(1) Levy  Frech> References are vague, but seem to be identical to CVE-1999-0940 | (XF:mutt-text-enriched-mime-bo). According to the references, the malformed | messages consist of metacharacters. In addition, -0941"s reference and | -0940"s SuSE reference both refer to fixes in 1.0pre3 release. Will | reconsider vote if other clearer references are forthcoming. | Christey> Modify to mention that the metachar"s are in the Content-Type header. | http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526154&w=2  View

Page 745 of 20943, showing 5 records out of 104715 total, starting on record 3721, ending on 3725

Actions