CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
283 | CVE-1999-0284 | Candidate | Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. | Proposed (19990623) | ACCEPT(2) Blake, Northcutt | MODIFY(3) Frech, Levy, Ozancin | NOOP(1) Baker | REVIEWING(1) Christey | Frech> "Windows NT-based mail servers" (A trademark thing, and for clarification) | XF:mdaemon-helo-bo | XF:lotus-notes-helo-crash | XF:slmail-helo-overflow | XF:smtp-helo-bo (mentions several products) | XF:smtp-exchangedos | Levy> - Need one per software. Each one should be its own | vulnerability. | Ozancin> => Windows NT is correct | Christey> These are probably multiple codebases, so we"ll need to use | dot notation. Also need to see if this should be merged | with CVE-1999-0098 (Sendmail SMTP HELO). | View |
964 | CVE-1999-0984 | Candidate | Matt"s Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | Proposed (19991214) | ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Cole | REVIEWING(1) Christey | Cole> How is this different than the previous? | Christey> More examination is required to determine if CVE-1999-0983, | CVE-1999-0984, or CVE-1999-0985 are the same codebase. | Frech> XF:matts-whois-meta | Christey> ADDREF BID:2000 | Christey> XF reference is gone. Replace with http-cgi-matts-whois-meta(3799) ? | View |
965 | CVE-1999-0985 | Candidate | CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | Proposed (19991214) | ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Cole | REVIEWING(1) Christey | Cole> I would combine all of these. | Christey> More examination is required to determine if CVE-1999-0983, | CVE-1999-0984, or CVE-1999-0985 are the same codebase. | Frech> XF:cc-whois-meta | Christey> ADDREF BID:2000 | Frech> Change cc-whois-meta(3800) to http-cgi-ccwhois(3747) | Christey> Replace XF reference with XF:cc-whois-meta(3800) ? | View |
893 | CVE-1999-0913 | Candidate | dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters. | Proposed (19991214) | ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(4) Armstrong, Baker, Cole, LeBlanc | REVIEWING(1) Christey | Christey> Some voters should use ABSTAIN. | Frech> XF:dragon-fire-ids-metachar(3834) | CHANGE> [Armstrong changed vote from REVIEWING to NOOP] | View |
1351 | CVE-1999-1371 | Candidate | Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument. | Modified (20040723) | ACCEPT(2) Cole, Dik | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | Frech> XF:solaris-write-bo(7546) | Christey> This appears to be a rediscovery of the problem for Solaris | 2.8: | BUGTRAQ:20011114 /usr/bin/write (solaris2.x) Segmentation Fault | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100588255815773&w=2 | Dik> sun bug: 4218941 | View |
Page 816 of 20943, showing 5 records out of 104715 total, starting on record 4076, ending on 4080