CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
163 | CVE-1999-0163 | Candidate | In older versions of Sendmail, an attacker could use a pipe character to execute root commands. | Proposed (19990714) | ACCEPT(2) Frech, Northcutt | MODIFY(1) Prosser | NOOP(2) Baker, Christey | RECAST(1) Shostack | Shostack> there was a "To: |" and a "From: |" attack, which I | think are seperate. | Prosser> older vulnerability, but one additional reference is- | The Ultimate Sendmail Hole List by Markus H・ner @ | bau2.uibk.ac.at/matic/buglist.htm | "|PROGRAM " | Christey> Description needs to be more specific to distinguish between | this and CVE-1999-0203, as alluded to by Adam Shostack | View |
171 | CVE-1999-0171 | Candidate | Denial of service in syslog by sending it a large number of superfluous messages. | Proposed (19990714) | ACCEPT(2) Frech, Northcutt | NOOP(1) Baker | REJECT(2) Christey, Shostack | Shostack> design issue, not a vulnerability. Alternately, add: | DOS on server by opening a large number of telnet sessions.. | Christey> Duplicate of CVE-1999-0566 | View |
463 | CVE-1999-0465 | Candidate | Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. | Proposed (19990728) | ACCEPT(2) Frech, Northcutt | NOOP(1) Baker | REJECT(2) LeBlanc, Wall | Wall> Reject based on client-side DoS | LeBlanc> Client side DOS | View |
306 | CVE-1999-0307 | Candidate | Buffer overflow in HP-UX cstm program allows local users to gain root privileges. | Modified (19991207-01) | ACCEPT(2) Frech, Northcutt | NOOP(3) Baker, Prosser, Shostack | RECAST(1) Christey | Prosser> only ref I can find is an old SOD exploit on | www.outpost9.com | Christey> MERGE CVE-1999-0336 (the exact exploit works with both | cstm and mstm, which are clearly part of the same package, | so CD:SF-EXEC says to merge them.) | | Also, there does not seem to be any recognition of this problem | by HP. The only other information besides the Bugtraq post | is the SOD exploit. | | See the original post: | http://www.securityfocus.com/templates/archive.pike?list=1&date=1996-11-15&msg=Pine.LNX.3.91.961116112242.15276J-100000@underground.org | View |
335 | CVE-1999-0336 | Candidate | Buffer overflow in mstm in HP-UX allows local users to gain root access. | Modified (19991207-01) | ACCEPT(2) Frech, Northcutt | NOOP(3) Baker, Prosser, Shostack | RECAST(1) Christey | Prosser> same as CVE-1999-0307, only ref I can find is an old SOD | exploit on www.outpost9.com | Christey> MERGE CVE-1999-0307 (the exact exploit works with both | cstm and mstm, which are clearly part of the same package, | so CD:SF-EXEC says to merge them.) | | Also, there does not seem to be any recognition of this problem | by HP. The only other information besides the Bugtraq post | is the SOD exploit. | View |
Page 880 of 20943, showing 5 records out of 104715 total, starting on record 4396, ending on 4400