CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
508 | CVE-1999-0511 | Candidate | IP forwarding is enabled on a machine which is not a router or firewall. | Proposed (19990726) | ACCEPT(2) Baker, Northcutt | MODIFY(1) Frech | Frech> XF:ip-forwarding | View |
512 | CVE-1999-0515 | Candidate | An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv. | Proposed (19990728) | ACCEPT(2) Baker, Northcutt | MODIFY(1) Frech | REJECT(1) Shostack | Shostack> Overly broad | Frech> XF:rsh-equiv(111) | Baker> Since this is unrestricted trust, I agree this is a problem | View |
527 | CVE-1999-0530 | Candidate | A system is operating in "promiscuous" mode which allows it to perform packet sniffing. | Proposed (19990728) | ACCEPT(2) Baker, Northcutt | MODIFY(1) Frech | REJECT(1) Shostack | Frech> XF:etherstatd(264) | XF:sniffer-attack(778) | XF:decod-packet-capture-remote(1072) | XF:netmon-running(1448) | XF:netxray3-probe(1450) | XF:sol-snoop-getquota-bo(3670) (also assigned to CVE-1999-0974) | Baker> Does pose a problem in non-switched environments | View |
330 | CVE-1999-0331 | Candidate | Buffer overflow in Internet Explorer 4.0(1). | Modified (20040811) | ACCEPT(2) Baker, Northcutt | MODIFY(2) Frech, Shostack | RECAST(1) Prosser | REJECT(2) Christey, LeBlanc | Shostack> this is a high cardinality item | Prosser> needs to be more specific. | Frech> Replace reference with XF:iemk-bug (msie-bo is obsolete and a vague | duplicate) | Description (from xfdb): Some versions of Internet Explorer for Windows | contain a vulnerability that may crash the broswer when a malicious web site | contains a certain kind of URL (that begins with "mk://") with more | characters than the browser supports. | Christey> The description is too vague. | LeBlanc> too vague | Christey> Add period to the end of the description. | View |
581 | CVE-1999-0599 | Candidate | A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers. | Proposed (19990726) | ACCEPT(2) Baker, Northcutt | NOOP(1) Frech | REVIEWING(1) Christey | Frech> Waiting for CIEL. | Christey> This is a design flaw, along with the other reported IDS | problems; at least reference Ptacek/Newsham"s paper. | Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html | View |
Page 802 of 20943, showing 5 records out of 104715 total, starting on record 4006, ending on 4010