CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2268 | CVE-2000-0692 | Candidate | ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set. | Modified (20001010-1) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> XF:realsecure-rskill-dos | Christey> CHANGEREF XF:realsecure-rskill-dos to XF:realsecure-frag-syn-dos? | http://xforce.iss.net/static/5133.php | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> In an email to issforum@iss.net on September 7, 2000, ISS says | that Network Sensor 3.2.2 is affected by SYN flooding, but | RealSecure 5.0 is not affected by Syn flooding. In addition, | they could not find conclusive evidence that RS 3.2.2 or 5.0 | was affected by IP fragmentation. This seems to indicate | that there are 2 *possible* problems: syn flooding (acknowledged | by ISS) and fragmentation (unconfirmed). Perhaps this | candidate needs to be split, or its description should be | rewritten to separate the 2 reported problems. | Frech> XF:realsecure-rskill-dos(5133) | View |
2311 | CVE-2000-0735 | Candidate | Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:becky-imail-header-dos | http://xforce.iss.net/static/5110.php | Frech> XF:becky-imail-header-dos(5110) | View |
2312 | CVE-2000-0736 | Candidate | Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:becky-imail-header-dos | http://xforce.iss.net/static/5110.php | Frech> XF:becky-imail-header-dos(5110) | View |
2263 | CVE-2000-0687 | Candidate | Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:cgi-auction-weaver-read-files | Christey> Need to double-check BID"s on all these Auction Weaver prob"s. | Frech> XF:cgi-auction-weaver-read-files(5150) | View |
2264 | CVE-2000-0688 | Candidate | Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:subscribe-me-overwrite-password | Christey> Make sure the mention of Account Manager is correct. | XF:subscribe-me-overwrite-password | http://xforce.iss.net/static/5126.php | Frech> XF:subscribe-me-overwrite-password(5126) | View |
Page 843 of 20943, showing 5 records out of 104715 total, starting on record 4211, ending on 4215