CVE List

Id CVE No. Status Description Phase Votes Comments Actions
163  CVE-1999-0163  Candidate  In older versions of Sendmail, an attacker could use a pipe character to execute root commands.  Proposed (19990714)  ACCEPT(2) Frech, Northcutt | MODIFY(1) Prosser | NOOP(2) Baker, Christey | RECAST(1) Shostack  Shostack> there was a "To: |" and a "From: |" attack, which I | think are seperate. | Prosser> older vulnerability, but one additional reference is- | The Ultimate Sendmail Hole List by Markus H・ner @ | bau2.uibk.ac.at/matic/buglist.htm | "|PROGRAM " | Christey> Description needs to be more specific to distinguish between | this and CVE-1999-0203, as alluded to by Adam Shostack  View
171  CVE-1999-0171  Candidate  Denial of service in syslog by sending it a large number of superfluous messages.  Proposed (19990714)  ACCEPT(2) Frech, Northcutt | NOOP(1) Baker | REJECT(2) Christey, Shostack  Shostack> design issue, not a vulnerability. Alternately, add: | DOS on server by opening a large number of telnet sessions.. | Christey> Duplicate of CVE-1999-0566  View
463  CVE-1999-0465  Candidate  Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.  Proposed (19990728)  ACCEPT(2) Frech, Northcutt | NOOP(1) Baker | REJECT(2) LeBlanc, Wall  Wall> Reject based on client-side DoS | LeBlanc> Client side DOS  View
306  CVE-1999-0307  Candidate  Buffer overflow in HP-UX cstm program allows local users to gain root privileges.  Modified (19991207-01)  ACCEPT(2) Frech, Northcutt | NOOP(3) Baker, Prosser, Shostack | RECAST(1) Christey  Prosser> only ref I can find is an old SOD exploit on | www.outpost9.com | Christey> MERGE CVE-1999-0336 (the exact exploit works with both | cstm and mstm, which are clearly part of the same package, | so CD:SF-EXEC says to merge them.) | | Also, there does not seem to be any recognition of this problem | by HP. The only other information besides the Bugtraq post | is the SOD exploit. | | See the original post: | http://www.securityfocus.com/templates/archive.pike?list=1&date=1996-11-15&msg=Pine.LNX.3.91.961116112242.15276J-100000@underground.org  View
335  CVE-1999-0336  Candidate  Buffer overflow in mstm in HP-UX allows local users to gain root access.  Modified (19991207-01)  ACCEPT(2) Frech, Northcutt | NOOP(3) Baker, Prosser, Shostack | RECAST(1) Christey  Prosser> same as CVE-1999-0307, only ref I can find is an old SOD | exploit on www.outpost9.com | Christey> MERGE CVE-1999-0307 (the exact exploit works with both | cstm and mstm, which are clearly part of the same package, | so CD:SF-EXEC says to merge them.) | | Also, there does not seem to be any recognition of this problem | by HP. The only other information besides the Bugtraq post | is the SOD exploit.  View

Page 880 of 20943, showing 5 records out of 104715 total, starting on record 4396, ending on 4400

Actions