CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
525 | CVE-1999-0528 | Candidate | A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. | Proposed (19990726) | ACCEPT(3) Baker, Meunier, Northcutt | MODIFY(1) Frech | Frech> possibly XF:nisd-dns-fwd-check | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:firewall-external-packet-forwarding(8372) | View |
607 | CVE-1999-0625 | Candidate | The rpc.rquotad service is running. | Proposed (19990721) | ACCEPT(3) Baker, Northcutt, Ozancin | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:rquotad | View |
606 | CVE-1999-0624 | Candidate | The rstat/rstatd service is running. | Interim (19990925) | ACCEPT(3) Baker, Northcutt, Ozancin | MODIFY(1) Frech | NOOP(2) Meunier, Wall | Frech> XF:rstat-out | XF:rstatd | View |
509 | CVE-1999-0512 | Candidate | A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers. | Modified (20020427-01) | ACCEPT(3) Baker, Northcutt, Shostack | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:smtp-sendmail-relay(210) | XF:ntmail-relay(2257) | XF:exchange-relay(3107) (also assigned to CVE-1999-0682) | XF:smtp-relay-uucp(3470) | XF:sco-sendmail-spam(4342) | XF:sco-openserver-mmdf-spam(4343) | XF:lotus-domino-smtp-mail-relay(6591) | XF:win2k-smtp-mail-relay(6803) | XF:cobalt-poprelayd-mail-relay(6806) | | Candidate implicitly may refer to relaying settings enabled by default, or | the bypass/circumvention of relaying. Both interpretations were used in | assigning this candidate. | Christey> The intention of this candidate is to cover configurations in | which the admin has explicitly enabled relaying. Other cases | in which the application *intends* to prvent relaying, but | there is some specific input that bypasses/tricks it, count | as vulnerabilities (or exposures?) and as such would be | assigned different numbers. | | http://www.sendmail.org/~ca/email/spam.html seems like a good | general resource, as does ftp://ftp.isi.edu/in-notes/rfc2505.txt | Christey> I changed the description to make it more clear that the issue | is that of explicit configuration, as opposed to being the | result of a vulnerability. | View |
498 | CVE-1999-0501 | Candidate | A Unix account has a guessable password. | Proposed (19990714) | ACCEPT(3) Baker, Northcutt, Shostack | RECAST(2) Frech, Meunier | REVIEWING(1) Christey | Frech> Guessable falls into the class of CVE-1999-0502, since I can guess a | default, null, etc. password. | Suggest changing to something like "has an existing non-default password | that can be guessed." | I"m also including default passwords in this entry. | In that vein, we show the following references: | XF:user-password | XF:passwd-username | XF:default-unix-sync | XF:default-unix-4dgifts | XF:default-unix-bin | XF:default-unix-daemon | XF:default-unix-lp | XF:default-unix-me | XF:default-unix-nuucp | XF:default-unix-root | XF:default-unix-toor | XF:default-unix-tour | XF:default-unix-tty | XF:default-unix-uucp | Christey> This candidate is affected by the CD:CF-PASS content decision, | which determines the appropriate level of abstraction to | use for password problems. CD:CF-PASS needs to be accepted | by the Editorial Board before this candidate can be | converted into a CVE entry; the final version of CD:CF-PASS | may require using a different LOA than this candidate is | currently using. | CHANGE> [Meunier changed vote from ACCEPT to RECAST] | Meunier> This relates only to account password technology, so this candidate is | independent of the operating system, application, web site or other | application of this technology. The appropriate (natural) level of | abstraction is therefore without specifying that it is for UNIX. | Change the description to "An account has a guessable password other | than default, null, blank." This should satisfy Andre"s objection. | | This Candidate should be merged with any candidate relating to | account password technology where "Unix" in the original description | can be replaced by something else. | View |
Page 953 of 20943, showing 5 records out of 104715 total, starting on record 4761, ending on 4765