CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2509 | CVE-2000-0940 | Candidate | Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter. | Proposed (20001129) | ACCEPT(2) Frech, Mell | NOOP(1) Cole | View | |
2508 | CVE-2000-0939 | Candidate | Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart. | Proposed (20001129) | ACCEPT(2) Frech, Mell | NOOP(1) Cole | REJECT(1) Renaud | Renaud> SWAT makes this DoS easier to perform, but actually, it is an inetd | problem, not a swat problem. | View |
2586 | CVE-2000-1017 | Candidate | Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database. | Proposed (20001129) | ACCEPT(2) Frech, Mell | NOOP(2) Cole, Wall | View | |
3144 | CVE-2001-0323 | Candidate | The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don"t Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host. | Modified (20131008) | ACCEPT(2) Frech, Meunier | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Christey> (prompted from Pascal Meunier) should this be treated | as a general design issue with ICMP? Or is it a specific | implementation flaw that only affects Reliant? | Meunier> It seems obvious that if one sets the MTU to just one byte | above the size of a IP header (let"s say 21 bytes), data transmission | is not going to go anywhere fast, as the overhead will be 20 times the | payload... As I said for another candidate, ICMP messages should not | be acted upon without access control. I"m not sure that references to | UNIX should be kept. It seems that this should work with any OS. It | would be nasty if some OSes accepted an MTU of 20, as you could not | transmit any IP data. | View |
169 | CVE-1999-0169 | Candidate | NFS allows attackers to read and write any file on the system by specifying a false UID. | Proposed (19990714) | ACCEPT(2) Frech, Northcutt | MODIFY(1) Baker | REJECT(1) Shostack | Shostack> this is not a vulnerability but a design feature. | Baker> Maybe we should reword it so that it is clear that this was a problem to something like: | | "A remote attacker could read/write files to the system with root-level permissions on NFS servers that fail to properly check the UID." | View |
Page 879 of 20943, showing 5 records out of 104715 total, starting on record 4391, ending on 4395