CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2391  CVE-2000-0817  Candidate  Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.  Modified (20010119-01)  ACCEPT(3) Baker, Cole, Mell | MODIFY(1) Frech | NOOP(1) Renaud  Frech> XF:network-monitor-bo(5399)  View
3613  CVE-2001-0807  Candidate  Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client"s hard drive via a SCRIPT tag with a SRC value that points to the text file.  Modified (20020226-01)  ACCEPT(3) Baker, Cole, Prosser | MODIFY(1) Frech | NOOP(3) Armstrong, Bishop, Foat | REVIEWING(2) Christey, Wall  Frech> XF:ie-local-file-disclosure(6688) | Prosser> Legacy product, users should have updated. | Courtesy of Microsoft Security Response Center <secure@microsoft.com>: | | IE 5 is no longer supported - so unless this repro"s on 5.01 or 5.5, we wouldn"t consider doing anything for this. | Christey> ADDREF BID:2836 | URL:http://www.securityfocus.com/bid/2836 | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
2608  CVE-2000-1039  Candidate  Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.  Proposed (20001219)  ACCEPT(3) Baker, Cole, Renaud | MODIFY(1) Frech | NOOP(2) Magdych, Wall | REVIEWING(1) Christey  Baker> Although this is at a high level, the fact is that it is a vulnerability, and as such we need to recognize this, even if we have to recast or modify the description at some later time. | Christey> This needs to be commented on and reviewed by many Board | members. | Frech> XF:naptha-resource-starvation(5810) | Christey> ADDREF SGI:20020304-01-A | Christey> SGI:20020304-01-A  View
3084  CVE-2001-0263  Candidate  Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.  Modified (20010222-02)  ACCEPT(3) Baker, Cole, Renaud | MODIFY(1) Frech | NOOP(3) Oliver, Wall, Ziese  Frech> XF:bpftp-obtain-credentials(6330)  View
983  CVE-1999-1003  Candidate  War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.  Proposed (19991222)  ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:warftp-connection-flood  View

Page 940 of 20943, showing 5 records out of 104715 total, starting on record 4696, ending on 4700

Actions