CVE List

Id CVE No. Status Description Phase Votes Comments Actions
283  CVE-1999-0284  Candidate  Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.  Proposed (19990623)  ACCEPT(2) Blake, Northcutt | MODIFY(3) Frech, Levy, Ozancin | NOOP(1) Baker | REVIEWING(1) Christey  Frech> "Windows NT-based mail servers" (A trademark thing, and for clarification) | XF:mdaemon-helo-bo | XF:lotus-notes-helo-crash | XF:slmail-helo-overflow | XF:smtp-helo-bo (mentions several products) | XF:smtp-exchangedos | Levy> - Need one per software. Each one should be its own | vulnerability. | Ozancin> => Windows NT is correct | Christey> These are probably multiple codebases, so we"ll need to use | dot notation. Also need to see if this should be merged | with CVE-1999-0098 (Sendmail SMTP HELO).  View
964  CVE-1999-0984  Candidate  Matt"s Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.  Proposed (19991214)  ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Cole | REVIEWING(1) Christey  Cole> How is this different than the previous? | Christey> More examination is required to determine if CVE-1999-0983, | CVE-1999-0984, or CVE-1999-0985 are the same codebase. | Frech> XF:matts-whois-meta | Christey> ADDREF BID:2000 | Christey> XF reference is gone. Replace with http-cgi-matts-whois-meta(3799) ?  View
965  CVE-1999-0985  Candidate  CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.  Proposed (19991214)  ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Cole | REVIEWING(1) Christey  Cole> I would combine all of these. | Christey> More examination is required to determine if CVE-1999-0983, | CVE-1999-0984, or CVE-1999-0985 are the same codebase. | Frech> XF:cc-whois-meta | Christey> ADDREF BID:2000 | Frech> Change cc-whois-meta(3800) to http-cgi-ccwhois(3747) | Christey> Replace XF reference with XF:cc-whois-meta(3800) ?  View
893  CVE-1999-0913  Candidate  dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.  Proposed (19991214)  ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(4) Armstrong, Baker, Cole, LeBlanc | REVIEWING(1) Christey  Christey> Some voters should use ABSTAIN. | Frech> XF:dragon-fire-ids-metachar(3834) | CHANGE> [Armstrong changed vote from REVIEWING to NOOP]  View
1351  CVE-1999-1371  Candidate  Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.  Modified (20040723)  ACCEPT(2) Cole, Dik | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:solaris-write-bo(7546) | Christey> This appears to be a rediscovery of the problem for Solaris | 2.8: | BUGTRAQ:20011114 /usr/bin/write (solaris2.x) Segmentation Fault | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100588255815773&w=2 | Dik> sun bug: 4218941  View

Page 816 of 20943, showing 5 records out of 104715 total, starting on record 4076, ending on 4080

Actions