CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61  CVE-1999-0061  Candidate  File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).  Proposed (19990630)  ACCEPT(3) Frech, Hill, Northcutt | RECAST(1) Baker | REVIEWING(1) Christey  Christey> This should be split into three separate problems based on | the SNI advisory. But there"s newer information to further | complicate things. | | What do we do about this one? in 1997 or so, SNI did an | advisory on this problem. In early 2000, it was still | discovered to be present in some Linux systems. So an | SF-DISCOVERY content decision might say that this is a | long enough time between the two, so this should be recorded | separately. But they"re the same codebase... so if we keep | them in the same entry, how do we make sure that this entry | reflects that some new information has been discovered? | | The use of dot notation may help in this regard, to use one | dot for the original problem as discovered in 1997, and | another dot for the resurgence of the problem in 2000. | Baker> We should merge these. | Christey> Perhaps this should be NAI-19 instead of NAI-20? | The original Bugtraq post for the SNI advisory suggests SNI-19: | BUGTRAQ:19971002 SNI-19:BSD lpd vulnerability | URL:SNI-19:BSD lpd vulnerability | | Also add: | BUGTRAQ:19971021 SNI-19: BSD lpd vulnerabilities (UPDATE) | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87747479514310&w=2 | | However, archives of "NAI-0020" point to the lpd vuln. | | If I recall correctly, some of the NAI advisory numbers got | switched when NAI acquired SNI.  View
2165  CVE-2000-0589  Candidate  SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.  Proposed (20000719)  ACCEPT(3) Frech, Levy, Magdych | NOOP(3) Cole, LeBlanc, Wall  CHANGE> [Magdych changed vote from REVIEWING to ACCEPT]  View
2184  CVE-2000-0608  Candidate  NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).  Proposed (20000719)  ACCEPT(3) Frech, Levy, Magdych | NOOP(3) Cole, LeBlanc, Wall    View
2185  CVE-2000-0609  Candidate  NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.  Proposed (20000719)  ACCEPT(3) Frech, Levy, Magdych | NOOP(3) Cole, LeBlanc, Wall    View
240  CVE-1999-0241  Candidate  Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.  Modified (19990925-01)  ACCEPT(3) Hill, Northcutt, Proctor | MODIFY(2) Frech, Prosser | NOOP(1) Baker | REVIEWING(1) Christey  Frech> Also add to references: | XF:sol-mkcookie | Prosser> additional source | Bugtraq | "X11 cookie hijacker" | http://www.securityfocus.com | Christey> The cookie hijacker thread has to do with stealing cookies | through a file with bad permissions. I"m not sure the | X-Force reference identifies this problem either. | Christey> CIAC:G-04 | URL:http://ciac.llnl.gov/ciac/bulletins/g-04.shtml | SGI:19960601-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/19960601-01-I | CERT:VB-95:08  View

Page 987 of 20943, showing 5 records out of 104715 total, starting on record 4931, ending on 4935

Actions