<?xml version="1.0"?>
<cve xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
     xmlns="http://cve.mitre.org/cve/downloads"
     xsi:noNamespaceSchemaLocation="http://cve.mitre.org/schema/cve/cve_1.0.xsd">
<item type="CAN" name="CVE-1999-0001" seq="1999-0001">
<status>Candidate</status>
<phase date="20051217">Modified</phase>
<desc>ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.</desc>
<refs>
<ref source="CERT">CA-98-13-tcp-denial-of-service</ref>
<ref source="BUGTRAQ">19981223 Re: CERT Advisory CA-98.13 - TCP/IP Denial of Service</ref>
<ref source="CONFIRM" url="http://www.openbsd.org/errata23.html#tcpfix">http://www.openbsd.org/errata23.html#tcpfix</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5707">5707</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Northcutt, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">A Bugtraq posting indicates that the bug has to do with
&quot;short packets with certain options set,&quot; so the description
should be modified accordingly.

But is this the same as CVE-1999-0052?  That one is related
to nestea (CVE-1999-0257) and probably the one described in
BUGTRAQ:19981023 nestea v2 against freebsd 3.0-Release
The patch for nestea is in ip_input.c around line 750.
The patches for CVE-1999-0001 are in lines 388&amp;446.  So, 
CVE-1999-0001 is different from CVE-1999-0257 and CVE-1999-0052.
The FreeBSD patch for CVE-1999-0052 is in line 750.
So, CVE-1999-0257 and CVE-1999-0052 may be the same, though
CVE-1999-0052 should be RECAST since this bug affects Linux
and other OSes besides FreeBSD.</comment>
<comment voter="Frech">XF:teardrop(338)
This assignment was based solely on references to the CERT advisory.</comment>
<comment voter="Christey">The description for BID:190, which links to CVE-1999-0052 (a
FreeBSD advisory), notes that the patches provided by FreeBSD in
CERT:CA-1998-13 suggest a connection between CVE-1999-0001 and
CVE-1999-0052.  CERT:CA-1998-13 is too vague to be sure without
further analysis.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0002" seq="1999-0002">
<status>Entry</status>
<desc>Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I">19981006-01-I</ref>
<ref source="CERT">CA-98.12.mountd</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-006.shtml">J-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/121">121</ref>
<ref source="XF">linux-mountd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0003" seq="1999-0003">
<status>Entry</status>
<desc>Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</desc>
<refs>
<ref source="NAI">NAI-29</ref>
<ref source="CERT">CA-98.11.tooltalk</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A">19981101-01-A</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX">19981101-01-PX</ref>
<ref source="XF">aix-ttdbserver</ref>
<ref source="XF">tooltalk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/122">122</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0004" seq="1999-0004">
<status>Candidate</status>
<phase date="19990621">Modified</phase>
<desc>MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.</desc>
<refs>
<ref source="CERT">CA-98.10.mime_buffer_overflows</ref>
<ref source="XF">outlook-long-name</ref>
<ref source="SUN">00175</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-008.asp">MS98-008</ref>
</refs>
<votes>
<accept count="8">Baker, Cole, Collins, Dik, Landfield, Magdych, Northcutt, Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
<reviewing count="1">Shostack</reviewing>
</votes>
<comments>
<comment voter="Frech">Extremely minor, but I believe e-mail is the correct term. (If you reject
this suggestion, I will not be devastated.) :-)</comment>
<comment voter="Christey">This issue seems to have been rediscovered in
BUGTRAQ:20000515 Eudora Pro &amp; Outlook Overflow - too long filenames again
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95842482413076&amp;w=2

Also see
BUGTRAQ:19990320 Eudora Attachment Buffer Overflow
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92195396912110&amp;w=2</comment>
<comment voter="Christey"> 
CVE-2000-0415 may be a later rediscovery of this problem
for Outlook.</comment>
<comment voter="Dik">Sun bug 4163471,</comment>
<comment voter="Christey">ADDREF BID:125</comment>
<comment voter="Christey">BUGTRAQ:19980730 Long Filenames &amp; Lotus Products
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526201&amp;w=2</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0005" seq="1999-0005">
<status>Entry</status>
<desc>Arbitrary command execution via IMAP buffer overflow in authenticate command.</desc>
<refs>
<ref source="CERT">CA-98.09.imapd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177">00177</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/130">130</ref>
<ref source="XF">imap-authenticate-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0006" seq="1999-0006">
<status>Entry</status>
<desc>Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.</desc>
<refs>
<ref source="CERT">CA-98.08.qpopper_vul</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I">19980801-01-I</ref>
<ref source="AUSCERT">AA-98.01</ref>
<ref source="XF">qpopper-pass-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/133">133</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0007" seq="1999-0007">
<status>Entry</status>
<desc>Information from SSL-encrypted sessions via PKCS #1.</desc>
<refs>
<ref source="CERT">CA-98.07.PKCS</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx">MS98-002</ref>
<ref source="XF">nt-ssl-fix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0008" seq="1999-0008">
<status>Entry</status>
<desc>Buffer overflow in NIS+, in Sun's rpc.nisd program.</desc>
<refs>
<ref source="CERT">CA-98.06.nisd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170">00170</ref>
<ref source="ISS">June10,1998</ref>
<ref source="XF">nisd-bo-check</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0009" seq="1999-0009">
<status>Entry</status>
<desc>Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="XF">bind-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/134">134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0010" seq="1999-0010">
<status>Entry</status>
<desc>Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="XF">bind-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0011" seq="1999-0011">
<status>Entry</status>
<desc>Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="XF">bind-axfr-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0012" seq="1999-0012">
<status>Entry</status>
<desc>Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</desc>
<refs>
<ref source="CERT">CA-98.04.Win32.WebServers</ref>
<ref source="XF">nt-web8.3</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0013" seq="1999-0013">
<status>Entry</status>
<desc>Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</desc>
<refs>
<ref source="CERT">CA-98.03.ssh-agent</ref>
<ref source="NAI">NAI-24</ref>
<ref source="XF">ssh-agent</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0014" seq="1999-0014">
<status>Entry</status>
<desc>Unauthorized privileged access or denial of service via dtappgather program in CDE.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075">HPSBUX9801-075</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185">00185</ref>
<ref source="CERT">CA-98.02.CDE</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0015" seq="1999-0015">
<status>Candidate</status>
<phase date="20090302">Modified</phase>
<desc>Teardrop IP denial of service.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5579">oval:org.mitre.oval:def:5579</ref>
<ref source="XF">teardrop</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF: teardrop-mod</comment>
<comment voter="Christey">Not sure how many separate &quot;instances&quot; of Teardrop there are.
See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258</comment>
<comment voter="Christey">See the SCO advisory at:
http://www.securityfocus.com/templates/advisory.html?id=1411
which may further clarify the issue.</comment>
<comment voter="Christey">MSKB:Q154174
MSKB:Q154174 (CVE-1999-0015) and MSKB:Q179129 (CVE-1999-0104)
indicate that CVE-1999-0015 was fixed in NT SP3, but
CVE-1999-0104 was not.  Thus CD:SF-LOC suggests that the
problems keep separate candidates because one problem appears
in a different version than the other.</comment>
<comment voter="Christey">BID:124
http://www.securityfocus.com/bid/124
Consider MSKB:Q154174
http://support.microsoft.com/support/kb/articles/q154/1/74.asp
Consider BUGTRAQ:19971113 Linux IP fragment overlap bug
http://www.securityfocus.com/archive/1/8014</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0016" seq="1999-0016">
<status>Entry</status>
<desc>Land IP denial of service.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="FREEBSD">FreeBSD-SA-98:01</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076">HPSBUX9801-076</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/land-pub.shtml</ref>
<ref source="XF">cisco-land</ref>
<ref source="XF">land</ref>
<ref source="XF">95-verv-tcp</ref>
<ref source="XF">land-patch</ref>
<ref source="XF">ver-tcpip-sys</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0017" seq="1999-0017">
<status>Entry</status>
<desc>FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</desc>
<refs>
<ref source="CERT">CA-97.27.FTP_bounce</ref>
<ref source="XF">ftp-bounce</ref>
<ref source="XF">ftp-privileged-port</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0018" seq="1999-0018">
<status>Entry</status>
<desc>Buffer overflow in statd allows root privileges.</desc>
<refs>
<ref source="CERT">CA-97.26.statd</ref>
<ref source="AUSCERT">AA-97.29</ref>
<ref source="XF">statd</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/127">127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0019" seq="1999-0019">
<status>Entry</status>
<desc>Delete or create a file via rpc.statd, due to invalid information.</desc>
<refs>
<ref source="CERT">CA-96.09.rpc.statd</ref>
<ref source="XF">rpc-stat</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0020" seq="1999-0020">
<status>Candidate</status>
<phase date="20050204">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0032.  Reason: This candidate is a duplicate of CVE-1999-0032.  Notes: All CVE users should reference CVE-1999-0032 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="4">Levy, Northcutt, Shostack, Wall</noop>
<reject count="2">Baker, Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:lpr-bo</comment>
<comment voter="Christey">DUPE CVE-1999-0032, which includes XF:lpr-bo</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0021" seq="1999-0021">
<status>Entry</status>
<desc>Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</desc>
<refs>
<ref source="BUGTRAQ">19971010 Security flaw in Count.cgi (wwwcount)</ref>
<ref source="CERT">CA-97.24.Count_cgi</ref>
<ref source="XF">http-cgi-count</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/128">128</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0022" seq="1999-0022">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via expstr() function.</desc>
<refs>
<ref source="CERT">CA-97.23.rdist</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref>
<ref source="XF">rdist-bo3</ref>
<ref source="XF">rdist-sept97</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0023" seq="1999-0023">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via lookup() function.</desc>
<refs>
<ref source="CERT">CA-96.14.rdist_vul</ref>
<ref source="XF">rdist-bo</ref>
<ref source="XF">rdist-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0024" seq="1999-0024">
<status>Entry</status>
<desc>DNS cache poisoning via BIND, by predictable query IDs.</desc>
<refs>
<ref source="CERT">CA-97.22.bind</ref>
<ref source="XF">bind</ref>
<ref source="NAI">NAI-11</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0025" seq="1999-0025">
<status>Entry</status>
<desc>root privileges via buffer overflow in df command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref>
<ref source="AUSCERT">AA-97.19.IRIX.df.buffer.overflow.vul</ref>
<ref source="SGI">SGI:19970505-01-A</ref>
<ref source="SGI">SGI:19970505-02-PX</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/440">df-bo(440)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0026" seq="1999-0026">
<status>Entry</status>
<desc>root privileges via buffer overflow in pset command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.20.IRIX.pset.buffer.overflow.vul</ref>
<ref source="XF">pset-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0027" seq="1999-0027">
<status>Entry</status>
<desc>root privileges via buffer overflow in eject command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.21.IRIX.eject.buffer.overflow.vul</ref>
<ref source="XF">eject-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0028" seq="1999-0028">
<status>Entry</status>
<desc>root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.22.IRIX.login.scheme.buffer.overflow.vul</ref>
<ref source="XF">sgi-schemebo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0029" seq="1999-0029">
<status>Entry</status>
<desc>root privileges via buffer overflow in ordist command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.23-IRIX.ordist.buffer.overflow.vul</ref>
<ref source="XF">ordist-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0030" seq="1999-0030">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>root privileges via buffer overflow in xlock command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.24.IRIX.xlock.buffer.overflow.vul</ref>
<ref source="XF">sgi-xlockbo</ref>
<ref source="SGI">19970508-02-PX</ref>
</refs>
<votes>
<accept count="3">Levy, Ozancin, Prosser</accept>
<noop count="1">Baker</noop>
<recast count="1">Frech</recast>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:xlock-bo (also add)
As per xlock-bo, also appears on AIX, BSDI, DG/UX, FreeBSD, Solaris, and
several Linii.
Also, don't you mean to cite SGI:19970502-02-PX? The one you list is
login/scheme.</comment>
<comment voter="Levy">Notice that this xlock overflow is the same as in
CA-97.13. CA-97.21 simply is a reminder.</comment>
<comment voter="Christey">As pointed out by Elias, CA-97.21 states: &quot;For more
information about vulnerabilities in xlock... see CA-97.13&quot;
CA-97.13 = CVE-1999-0038.
This may also be a duplicate with CVE-1999-0306.

See exploits at:

http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418394&amp;w=2
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418404&amp;w=2

Sun also has this problem, at
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/150&amp;type=0&amp;nav=sec.sba</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0031" seq="1999-0031">
<status>Entry</status>
<desc>JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</desc>
<refs>
<ref source="CERT">CA-97.20.javascript</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0032" seq="1999-0032">
<status>Entry</status>
<desc>Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</desc>
<refs>
<ref source="BUGTRAQ">19960813 Possible bufferoverflow condition in lpr, xterm and xload</ref>
<ref source="BUGTRAQ">19961025 Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[freebsd-security] 19961025 Vadim Kolontsov: BoS: Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[linux-security] 19961122 LSF Update#14: Vulnerability of the lpr program.</ref>
<ref source="CERT">CA-97.19.bsdlp</ref>
<ref source="AUSCERT">AA-96.12</ref>
<ref source="CIAC">H-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref>
<ref source="XF">bsd-lprbo2</ref>
<ref source="XF">bsd-lprbo</ref>
<ref source="XF">lpr-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0033" seq="1999-0033">
<status>Candidate</status>
<phase date="20040811">Modified</phase>
<desc>Command execution in Sun systems via buffer overflow in the at program.</desc>
<refs>
<ref source="CERT">CA-97.18.at</ref>
<ref source="SUN">00160</ref>
<ref source="XF">sun-atbo</ref>
</refs>
<votes>
<accept count="8">Baker, Cole, Collins, Dik, Hill, Northcutt, Shostack, Wall</accept>
<noop count="1">Christey</noop>
<recast count="1">Frech</recast>
</votes>
<comments>
<comment voter="Frech">This vulnerability also manifests itself for the following 
platforms: AIX, HPUX, IRIX, Solaris, SCO, NCR MP-RAS. In this light,
please add the following:
Reference: XF:at-bo</comment>
<comment voter="Dik">Sun bug 1265200, 4063161</comment>
<comment voter="Christey">ADDREF SGI:19971102-01-PX
ftp://patches.sgi.com/support/free/security/advisories/19971102-01-PX
SCO:SB.97:01
ftp://ftp.sco.com/SSE/security_bulletins/SB.97:01a</comment>
<comment voter="Christey">CIAC:F-15
http://ciac.llnl.gov/ciac/bulletins/f-15.shtml
HP:HPSBUX9502-023</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0034" seq="1999-0034">
<status>Entry</status>
<desc>Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</desc>
<refs>
<ref source="CERT">CA-97.17.sperl</ref>
<ref source="XF">perl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0035" seq="1999-0035">
<status>Entry</status>
<desc>Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</desc>
<refs>
<ref source="XF">ftp-ftpd</ref>
<ref source="CERT">CA-97.16.ftpd</ref>
<ref source="AUSCERT">AA-97.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0036" seq="1999-0036">
<status>Entry</status>
<desc>IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</desc>
<refs>
<ref source="CERT">CA-97.15.sgi_login</ref>
<ref source="AUSCERT">AA-97.12</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref>
<ref source="OSVDB" url="http://www.osvdb.org/990">990</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/557">sgi-lockout(557)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0037" seq="1999-0037">
<status>Entry</status>
<desc>Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</desc>
<refs>
<ref source="CERT">CA-97.14.metamail</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0038" seq="1999-0038">
<status>Entry</status>
<desc>Buffer overflow in xlock program allows local users to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-97.13.xlock</ref>
<ref source="XF">xlock-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0039" seq="1999-0039">
<status>Entry</status>
<desc>webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</desc>
<refs>
<ref source="BUGTRAQ">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in</ref>
<ref source="BUGTRAQ">19970507 Re: SGI Advisory: webdist.cgi</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref>
<ref source="AUSCERT">AA-97.14</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref>
<ref source="OSVDB" url="http://www.osvdb.org/235">235</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/333">http-sgi-webdist(333)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0040" seq="1999-0040">
<status>Entry</status>
<desc>Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.11.libXt</ref>
<ref source="XF">libXt-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0041" seq="1999-0041">
<status>Entry</status>
<desc>Buffer overflow in NLS (Natural Language Service).</desc>
<refs>
<ref source="CERT">CA-97.10.nls</ref>
<ref source="XF">nls-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0042" seq="1999-0042">
<status>Entry</status>
<desc>Buffer overflow in University of Washington's implementation of IMAP and POP servers.</desc>
<refs>
<ref source="NAI">NAI-21</ref>
<ref source="CERT">CA-97.09.imap_pop</ref>
<ref source="XF">popimap-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0043" seq="1999-0043">
<status>Entry</status>
<desc>Command execution via shell metachars in INN daemon (innd) 1.5 using &quot;newgroup&quot; and &quot;rmgroup&quot; control messages, and others.</desc>
<refs>
<ref source="CERT">CA-97.08.innd</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0044" seq="1999-0044">
<status>Entry</status>
<desc>fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref>
<ref source="XF">sgi-fsdump</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0045" seq="1999-0045">
<status>Entry</status>
<desc>List of arbitrary files on Web host via nph-test-cgi script.</desc>
<refs>
<ref source="CERT">CA-97.07.nph-test-cgi_script</ref>
<ref source="XF">http-cgi-nph</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0046" seq="1999-0046">
<status>Entry</status>
<desc>Buffer overflow of rlogin program using TERM environmental variable.</desc>
<refs>
<ref source="CERT">CA-97.06.rlogin-term</ref>
<ref source="XF">rlogin-termbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0047" seq="1999-0047">
<status>Entry</status>
<desc>MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</desc>
<refs>
<ref source="CERT">CA-97.05.sendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref>
<ref source="XF">sendmail-mime-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0048" seq="1999-0048">
<status>Entry</status>
<desc>Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.04.talkd</ref>
<ref source="FREEBSD">FreeBSD-SA-96:21</ref>
<ref source="AUSCERT">AA-97.01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref>
<ref source="XF">talkd-bo</ref>
<ref source="XF">netkit-talkd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0049" seq="1999-0049">
<status>Entry</status>
<desc>Csetup under IRIX allows arbitrary file creation or overwriting.</desc>
<refs>
<ref source="XF">sgi-csetup</ref>
<ref source="CERT">CA-97.03.csetup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0050" seq="1999-0050">
<status>Entry</status>
<desc>Buffer overflow in HP-UX newgrp program.</desc>
<refs>
<ref source="CERT">CA-97.02.hp_newgrp</ref>
<ref source="AUSCERT">AA-96.16.HP-UX.newgrp.Buffer.Overrun.Vulnerability</ref>
<ref source="XF">hp-newgrpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0051" seq="1999-0051">
<status>Entry</status>
<desc>Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</desc>
<refs>
<ref source="XF">sgi-licensemanager</ref>
<ref source="CERT">CA-97.01.flex_lm</ref>
<ref source="AUSCERT">AA-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0052" seq="1999-0052">
<status>Entry</status>
<desc>IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:08</ref>
<ref source="OSVDB" url="http://www.osvdb.org/908">908</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1389">freebsd-ip-frag-dos(1389)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0053" seq="1999-0053">
<status>Entry</status>
<desc>TCP RST denial of service in FreeBSD.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:07</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6094">6094</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0054" seq="1999-0054">
<status>Entry</status>
<desc>Sun's ftpd daemon can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171">00171</ref>
<ref source="XF">sun-ftpd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0055" seq="1999-0055">
<status>Entry</status>
<desc>Buffer overflows in Sun libnsl allow root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172">00172</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only">IX80543</ref>
<ref source="RSI">RSI.0005.05-14-98.SUN.LIBNSL</ref>
<ref source="XF">sun-libnsl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0056" seq="1999-0056">
<status>Entry</status>
<desc>Buffer overflow in Sun's ping program can give root access to local users.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174">00174</ref>
<ref source="XF">sun-ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0057" seq="1999-0057">
<status>Entry</status>
<desc>Vacation program allows command execution by remote users through a sendmail command.</desc>
<refs>
<ref source="NAI">NAI-19</ref>
<ref source="XF">vacation</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087">HPSBUX9811-087</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0058" seq="1999-0058">
<status>Entry</status>
<desc>Buffer overflow in PHP cgi program, php.cgi allows shell access.</desc>
<refs>
<ref source="NAI">NAI-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref>
<ref source="XF">http-cgi-phpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0059" seq="1999-0059">
<status>Entry</status>
<desc>IRIX fam service allows an attacker to obtain a list of all files on the server.</desc>
<refs>
<ref source="NAI">NAI-16</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref>
<ref source="OSVDB" url="http://www.osvdb.org/164">164</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/325">irix-fam(325)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0060" seq="1999-0060">
<status>Entry</status>
<desc>Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</desc>
<refs>
<ref source="NAI">NAI-26</ref>
<ref source="XF">ascend-config-kill</ref>
<ref source="ASCEND">http://www.ascend.com/2695.html</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0061" seq="1999-0061">
<status>Candidate</status>
<phase date="19990630">Proposed</phase>
<desc>File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).</desc>
<refs>
<ref source="NAI">NAI-20</ref>
<ref source="XF">bsd-lpd</ref>
</refs>
<votes>
<accept count="3">Frech, Hill, Northcutt</accept>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">This should be split into three separate problems based on
the SNI advisory.  But there's newer information to further
complicate things.

What do we do about this one?  in 1997 or so, SNI did an
advisory on this problem.  In early 2000, it was still
discovered to be present in some Linux systems.  So an 
SF-DISCOVERY content decision might say that this is a
long enough time between the two, so this should be recorded
separately.  But they're the same codebase... so if we keep
them in the same entry, how do we make sure that this entry
reflects that some new information has been discovered?

The use of dot notation may help in this regard, to use one
dot for the original problem as discovered in 1997, and
another dot for the resurgence of the problem in 2000.</comment>
<comment voter="Baker">We should merge these.</comment>
<comment voter="Christey">Perhaps this should be NAI-19 instead of NAI-20?
The original Bugtraq post for the SNI advisory suggests SNI-19:
BUGTRAQ:19971002 SNI-19:BSD lpd vulnerability
URL:SNI-19:BSD lpd vulnerability

Also add:
BUGTRAQ:19971021 SNI-19: BSD lpd vulnerabilities (UPDATE)
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87747479514310&amp;w=2

However, archives of &quot;NAI-0020&quot; point to the lpd vuln.

If I recall correctly, some of the NAI advisory numbers got
switched when NAI acquired SNI.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0062" seq="1999-0062">
<status>Entry</status>
<desc>The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</desc>
<refs>
<ref source="XF">openbsd-chpass</ref>
<ref source="NAI">NAI-28</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7559">7559</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0063" seq="1999-0063">
<status>Entry</status>
<desc>Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</desc>
<refs>
<ref source="AUSCERT">ESB-98.197</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/iossyslog-pub.shtml</ref>
<ref source="XF">cisco-syslog-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0064" seq="1999-0064">
<status>Entry</status>
<desc>Buffer overflow in AIX lquerylv program gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">May28,1997</ref>
<ref source="XF">lquerylv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0065" seq="1999-0065">
<status>Entry</status>
<desc>Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181">00181</ref>
<ref source="XF">hp-dtmail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0066" seq="1999-0066">
<status>Entry</status>
<desc>AnyForm CGI remote execution.</desc>
<refs>
<ref source="BUGTRAQ">19950731 SECURITY HOLE: &quot;AnyForm&quot; CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref>
<ref source="XF">http-cgi-anyform</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0067" seq="1999-0067">
<status>Entry</status>
<desc>phf CGI program allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19960923 PHF Attacks - Fun and games for the whole family</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref>
<ref source="AUSCERT">AA-96.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref>
<ref source="OSVDB" url="http://www.osvdb.org/136">136</ref>
<ref source="XF">http-cgi-phf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0068" seq="1999-0068">
<status>Entry</status>
<desc>CGI PHP mylog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="XF">http-cgi-php-mylog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3396">3396</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0069" seq="1999-0069">
<status>Entry</status>
<desc>Solaris ufsrestore buffer overflow.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169">00169</ref>
<ref source="XF">sun-ufsrestore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8158">8158</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0070" seq="1999-0070">
<status>Entry</status>
<desc>test-cgi program allows an attacker to list files on the server.</desc>
<refs>
<ref source="XF">http-cgi-test</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0071" seq="1999-0071">
<status>Entry</status>
<desc>Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</desc>
<refs>
<ref source="XF">http-apache-cookie</ref>
<ref source="NAI">NAI-2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0072" seq="1999-0072">
<status>Entry</status>
<desc>Buffer overflow in AIX xdat gives root access to local users.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:004.1</ref>
<ref source="XF">ibm-xdat</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0073" seq="1999-0073">
<status>Entry</status>
<desc>Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</desc>
<refs>
<ref source="CERT">CA-95:14.Telnetd_Environment_Vulnerability</ref>
<ref source="XF">linkerbug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0074" seq="1999-0074">
<status>Entry</status>
<desc>Listening TCP ports are sequentially allocated, allowing spoofing attacks.</desc>
<refs>
<ref source="XF">seqport</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0075" seq="1999-0075">
<status>Entry</status>
<desc>PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</desc>
<refs>
<ref source="BUGTRAQ">19961016 Re: ftpd bug? Was: bin/1805: Bug in ftpd</ref>
<ref source="XF">ftp-pasvcore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5742">5742</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0076" seq="1999-0076">
<status>Candidate</status>
<phase date="19990925">Modified</phase>
<desc>Buffer overflow in wu-ftp from PASV command causes a core dump.</desc>
<refs>
<ref source="XF">ftp-args</ref>
</refs>
<votes>
<accept count="3">Baker, Frech, Ozancin</accept>
<noop count="1">Balinsky</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Balinsky">Don't know what this is.  Is this the LIST Core dump vulnerability?</comment>
<comment voter="Christey">Need to add more references and details.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0077" seq="1999-0077">
<status>Entry</status>
<desc>Predictable TCP sequence numbers allow spoofing.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0078" seq="1999-0078">
<status>Candidate</status>
<phase date="19990621">Modified</phase>
<desc>pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</desc>
<refs>
<ref source="CERT">CA-96.08.pcnfsd</ref>
<ref source="XF">rpc-pcnfsd</ref>
</refs>
<votes>
<accept count="5">Collins, Frech, Landfield, Northcutt, Shostack</accept>
<noop count="1">Baker</noop>
<recast count="1">Christey</recast>
</votes>
<comments>
<comment voter="Christey">This candidate should be SPLIT, since there are two separate
software flaws.  One is a symlink race and the other is a
shell metacharacter problem.</comment>
<comment voter="Christey">The permissions part of this vulnerability appears to
overlap with CVE-1999-0353</comment>
<comment voter="Christey">SGI:20020802-01-I</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0079" seq="1999-0079">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</desc>
<refs>
<ref source="XF">ftp-pasv-dos</ref>
<ref source="XF">ftp-pasvdos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0080" seq="1999-0080">
<status>Entry</status>
<desc>Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the &quot;site exec&quot; command.</desc>
<refs>
<ref source="BUGTRAQ">19950531 SECURITY: problem with some wu-ftpd-2.4 binaries (fwd)</ref>
<ref source="CERT">CA-95:16.wu-ftpd.vul</ref>
<ref source="XF">ftp-execdotdot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0081" seq="1999-0081">
<status>Entry</status>
<desc>wu-ftp allows files to be overwritten via the rnfr command.</desc>
<refs>
<ref source="XF">ftp-rnfr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0082" seq="1999-0082">
<status>Entry</status>
<desc>CWD ~root command in ftpd allows root access.</desc>
<refs>
<ref source="XF">ftp-cwd</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0083" seq="1999-0083">
<status>Entry</status>
<desc>getcwd() file descriptor leak in FTP.</desc>
<refs>
<ref source="XF">cwdleak</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0084" seq="1999-0084">
<status>Entry</status>
<desc>Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0085" seq="1999-0085">
<status>Entry</status>
<desc>Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</desc>
<refs>
<ref source="BUGTRAQ">19960821 rwhod buffer overflow</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0086" seq="1999-0086">
<status>Candidate</status>
<phase date="19990630">Interim</phase>
<desc>AIX routed allows remote users to modify sensitive files.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1998:001.1</ref>
<ref source="XF">ibm-routed</ref>
</refs>
<votes>
<accept count="2">Northcutt, Shostack</accept>
<modify count="2">Frech, Prosser</modify>
<noop count="1">Baker</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">Reference: XF:ibm-routed</comment>
<comment voter="Prosser">This vulnerability allows debug mode to be turned on which is
the problem.  Should this be more specific in the description? This
one also affects SGI OSes, ref SGI Security Advisory 19981004-PX which
is in the SGI cluster, shouldn't these be cross-referenced as the same
vuln affects multiple OSes.</comment>
<comment voter="Christey">This appears to be subsumed by CVE-1999-0215</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0087" seq="1999-0087">
<status>Entry</status>
<desc>Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</desc>
<refs>
<ref source="XF">ibm-telnetdos</ref>
<ref source="ERS">ERS-SVA-E01-1998:003.1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7992">7992</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0088" seq="1999-0088">
<status>Candidate</status>
<phase date="19990617">Proposed</phase>
<desc>IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.</desc>
<refs>
<ref source="ERS" url="http://www-1.ibm.com/services/brs/brspwhub.nsf/advisories/852567CC004F9038852566BF007B6393/$file/ERS-SVA-E01-1998_004_1.txt">ERS-SVA-E01-1998:004.1</ref>
</refs>
<votes>
<accept count="2">Northcutt, Shostack</accept>
<modify count="2">Frech, Prosser</modify>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">ERS (and other references, BTW) explicitly stipulate 'local and
remote'.
Reference: XF:irix-autofsd</comment>
<comment voter="Prosser">Include the SGI Alert as well since it is mentioned in the
description.
SGI Security Advisory 19981005-01-PX</comment>
<comment voter="Christey">DUPE CVE-1999-0210?</comment>
<comment voter="Christey">ADDREF CIAC:J-014</comment>
<comment voter="Baker">It does look very similar to 1999-0210.  Perhaps they should be a single entry</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0089" seq="1999-0089">
<status>Candidate</status>
<phase date="19990630">Interim</phase>
<desc>Buffer overflow in AIX libDtSvc library can allow local users to gain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-libDtSvc</ref>
</refs>
<votes>
<accept count="2">Northcutt, Shostack</accept>
<modify count="2">Frech, Prosser</modify>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Reference: XF:ibm-libDtSvc</comment>
<comment voter="Prosser">The overflow is in the dtaction utility.  Also affects
dtaction in the CDE on versions of SunOS (SUN 164). Probably should be
specific.</comment>
<comment voter="Christey">Same Codebase as CVE-1999-0121, so the two entries should be
merged.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0090" seq="1999-0090">
<status>Entry</status>
<desc>Buffer overflow in AIX rcp command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-rcp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0091" seq="1999-0091">
<status>Entry</status>
<desc>Buffer overflow in AIX writesrv command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-writesrv</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0092" seq="1999-0092">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>Various vulnerabilities in the AIX portmir command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:006.1</ref>
</refs>
<votes>
<accept count="2">Baker, Bollinger</accept>
<modify count="1">Frech</modify>
<noop count="1">Ozancin</noop>
</votes>
<comments>
<comment voter="Frech">XF:ibm-portmir</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0093" seq="1999-0093">
<status>Entry</status>
<desc>AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:008.1</ref>
<ref source="XF">ibm-nslookup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0094" seq="1999-0094">
<status>Entry</status>
<desc>AIX piodmgrsu command allows local users to gain additional group privileges.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:007.1</ref>
<ref source="XF">ibm-piodmgrsu</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0095" seq="1999-0095">
<status>Entry</status>
<desc>The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-88.01</ref>
<ref source="CERT">CA-93.14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/195">195</ref>
<ref source="XF">smtp-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0096" seq="1999-0096">
<status>Entry</status>
<desc>Sendmail decode alias can be used to overwrite sensitive files.</desc>
<refs>
<ref source="CERT">CA-93.16</ref>
<ref source="CERT">CA-95.05</ref>
<ref source="CIAC">A-13</ref>
<ref source="CIAC">A-14</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
<ref source="XF">smtp-dcod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0097" seq="1999-0097">
<status>Entry</status>
<desc>The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:009.1</ref>
<ref source="XF">ibm-ftp</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0098" seq="1999-0098">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.</desc>
<refs>
<ref source="XF">smtp-helo-bo</ref>
</refs>
<votes>
<modify count="2">Baker, Frech</modify>
<noop count="1">Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">(Accept XF reference.)
Our references do not mention hiding activities. This issue can crash the
SMTP server or execute arbitrary byte-code. Is there another reference
available?</comment>
<comment voter="Christey">Should this be merged with CVE-1999-0284, which is Sendmail
with SMTP HELO?</comment>
<comment voter="Christey">BUGTRAQ:19980522 about sendmail 8.8.8 HELO hole
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925991&amp;w=2
BUGTRAQ:19980527 about sendmail 8.8.8 HELO hole
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926003&amp;w=2</comment>
<comment voter="Baker">Apparently this XF reference is not for this issue, but for the other issue.  This should be modified to have the Bugtraq references, and remove the XF reference.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0099" seq="1999-0099">
<status>Entry</status>
<desc>Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-95.13.syslog.vul</ref>
<ref source="XF">smtp-syslog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0100" seq="1999-0100">
<status>Entry</status>
<desc>Remote access in AIX innd 1.5.1, using control messages.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:002.1</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0101" seq="1999-0101">
<status>Entry</status>
<desc>Buffer overflow in AIX and Solaris &quot;gethostbyname&quot; library call allows root access through corrupt DNS host names.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:001.1</ref>
<ref source="ERS">ERS-SVA-E01-1996:007.1</ref>
<ref source="SUN">00137a</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</ref>
<ref source="NAI">NAI-1</ref>
<ref source="XF">ghbn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0102" seq="1999-0102">
<status>Entry</status>
<desc>Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</desc>
<refs>
<ref source="XF">slmail-fromheader-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0103" seq="1999-0103">
<status>Entry</status>
<desc>Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</desc>
<refs>
<ref source="CERT">CA-96.01.UDP_service_denial</ref>
<ref source="XF">echo</ref>
<ref source="XF">chargen</ref>
<ref source="XF">chargen-patch</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0104" seq="1999-0104">
<status>Candidate</status>
<phase date="20090302">Modified</phase>
<desc>A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5743">oval:org.mitre.oval:def:5743</ref>
<ref source="XF">teardrop-mod</ref>
</refs>
<votes>
<accept count="2">Frech, Wall</accept>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Wall">Another reference is Microsoft Knowledge Base Q179129.</comment>
<comment voter="Christey">Not sure how many separate &quot;instances&quot; of Teardrop there are.
See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258</comment>
<comment voter="Christey">See the SCO advisory at:
http://www.securityfocus.com/templates/advisory.html?id=1411
which may further clarify the issue.</comment>
<comment voter="Christey">MSKB:Q179129
http://support.microsoft.com/support/kb/articles/q179/1/29.asp</comment>
<comment voter="Christey">MSKB:Q179129
http://support.microsoft.com/support/kb/articles/q179/1/29.asp
Note that the hotfix name is teardrop2, but the keywords
included in the KB article specifically name bonk
(CVE-1999-0258) and boink.
Since teardrop2 was fixed in a slightly different version
(at least in a separate patch) than Teardrop, CD:SF-LOC
suggests keeping them separate.</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0105" seq="1999-0105">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>finger allows recursive searches by using a long string of @ symbols.</desc>
<refs>
</refs>
<votes>
<modify count="3">Baker, Frech, Shostack</modify>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Shostack">fingerD</comment>
<comment voter="Frech">XF:finger-bomb</comment>
<comment voter="Christey">aka redirection or forwarding requests? (but then might
overlap CVE-1999-0106)</comment>
<comment voter="Baker">should change description to indicate the recursive searching can consume enough system resources to cause a DoS.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0106" seq="1999-0106">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Finger redirection allows finger bombs.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<modify count="2">Frech, Shostack</modify>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Shostack">fingerd allows redirection
This is a larger modification, since there are two applications of the 
vulnerability, one that I can finger anonymously, and the other that I 
can finger bomb anonymously.</comment>
<comment voter="Frech">XF:finger-bomb</comment>
<comment voter="Christey">need more refs</comment>
<comment voter="Baker">This should be merged with 1999-0105</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0107" seq="1999-0107">
<status>Candidate</status>
<phase date="19991223">Modified</phase>
<desc>Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.</desc>
<refs>
<ref source="XF">apache-dos</ref>
<ref source="BUGTRAQ">19971230 Apache DoS attack?</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="3">Northcutt, Shostack, Wall</noop>
<reviewing count="1">Levy</reviewing>
<revote count="1">Christey</revote>
</votes>
<comments>
<comment voter="Wall">- Although this is probably the phf hack.</comment>
<comment voter="Frech">XF:apache-dos</comment>
<comment voter="Christey">This sounds like the incident reported in:
NTBUGTRAQ:20000810 Apache Distributed Denial of Service</comment>
<comment voter="Levy">I belive this is the problem where sending lot of HTTP headers to apache resulted on a denial of service.
BUGTRAQ: http://www.securityfocus.com/archive/1/10228
BUGTRAQ: http://www.securityfocus.com/archive/1/10516</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0108" seq="1999-0108">
<status>Entry</status>
<desc>The printers program in IRIX has a buffer overflow that gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">another day, another buffer overflow...</ref>
<ref source="XF">printers-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0109" seq="1999-0109">
<status>Entry</status>
<desc>Buffer overflow in ffbconfig in Solaris 2.5.1.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref>
<ref source="AUSCERT">AA-97.06</ref>
<ref source="XF">ffbconfig-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0110" seq="1999-0110">
<status>Candidate</status>
<phase date="19990810">Interim</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0315.  Reason: This candidate's original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315.  Notes: All CVE users should reference CVE-1999-0315 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="4">Levy, Northcutt, Shostack, Wall</noop>
<reject count="3">Baker, Christey, Dik</reject>
</votes>
<comments>
<comment voter="Frech">XF:fdformat-bo</comment>
<comment voter="Christey">Duplicate of CVE-1999-0315</comment>
<comment voter="Dik">dup</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0111" seq="1999-0111">
<status>Entry</status>
<desc>RIP v1 is susceptible to spoofing.</desc>
<refs>
<ref source="XF">rip</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0112" seq="1999-0112">
<status>Entry</status>
<desc>Buffer overflow in AIX dtterm program for the CDE.</desc>
<refs>
<ref source="BUGTRAQ">19970520 AIX 4.2 dtterm exploit</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/878">dtterm-bo(878)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0113" seq="1999-0113">
<status>Entry</status>
<desc>Some implementations of rlogin allow root access if given a -froot parameter.</desc>
<refs>
<ref source="BUGTRAQ">19940729 -froot??? (AIX rlogin bug)</ref>
<ref source="CERT">CA-94.09.bin.login.vulnerability</ref>
<ref source="CIAC">E-26</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref>
<ref source="XF">rlogin-froot</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0114" seq="1999-0114">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19990912 elm filter program</ref>
<ref source="BUGTRAQ">19951226 filter (elm package) security hole</ref>
<ref source="XF">elm-filter2</ref>
</refs>
<votes>
<accept count="7">Armstrong, Bishop, Blake, Cole, Landfield, Shostack, Wall</accept>
<modify count="2">Baker, Frech</modify>
<noop count="3">Christey, Northcutt, Ozancin</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:elm-filter2</comment>
<comment voter="CHANGE">[Wall changed vote from NOOP to ACCEPT]</comment>
<comment voter="Landfield">with Frech modifications</comment>
<comment voter="Baker">ADD REF http://www.cert.org/ftp/cert_bulletins/VB-95:10a.elm	Official Advisory</comment>
<comment voter="Christey">The correct URL is http://www.cert.org/vendor_bulletins/VB-95:10a.elm
Need to make sure that this CERT advisory describes the right
problem, especially since the CERT advisory is dated December
18, 1995 and the original Bugtraq post was December 26, 1995.</comment>
<comment voter="Christey">BID:1802
URL:http://www.securityfocus.com/bid/1802
BID:1802 doesn't include the 1999 posting - does Security
Focus think that the 1999 post describes a different
vulnerability?</comment>
<comment voter="Christey">XF:elm-filter2 isn't on the X-Force web site.  How about XF:elm-filter(402) ?
Its references point to the December 26, 1995 BUgtraq post.

Also consider CIAC:G-36 and CERT:VB-95:10</comment>
<comment voter="Frech">DELREF:XF:elm-filter2(711)
ADDREF:XF:elm-filter(402)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0115" seq="1999-0115">
<status>Entry</status>
<desc>AIX bugfiler program allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ">19970909 AIX bugfiler</ref>
<ref source="XF">ibm-bugfiler</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0116" seq="1999-0116">
<status>Entry</status>
<desc>Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</desc>
<refs>
<ref source="CERT">CA-96.21.tcp_syn.flooding</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0117" seq="1999-0117">
<status>Entry</status>
<desc>AIX passwd allows local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-passwd</ref>
<ref source="CERT">CA-92:07.AIX.passwd.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0118" seq="1999-0118">
<status>Entry</status>
<desc>AIX infod allows local users to gain root access through an X display.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2">19981119 RSI.0011.11-09-98.AIX.INFOD</ref>
<ref source="XF">aix-infod</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0119" seq="1999-0119">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Windows NT 4.0 beta allows users to read and delete shares.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Baker, Northcutt</noop>
<reject count="1">Wall</reject>
</votes>
<comments>
<comment voter="Wall">Reject based on beta copy.</comment>
<comment voter="Frech">XF:nt-beta(11)
Reconsider reject, because this beta was in widespread use.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0120" seq="1999-0120">
<status>Entry</status>
<desc>Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref>
<ref source="CERT">CA-94.06.utmp.vulnerability</ref>
<ref source="XF">utmp-write</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0121" seq="1999-0121">
<status>Candidate</status>
<phase date="19990617">Proposed</phase>
<desc>Buffer overflow in dtaction command gives root access.</desc>
<refs>
<ref source="SUN">00164</ref>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
</refs>
<votes>
<accept count="2">Dik, Northcutt</accept>
<modify count="3">Baker, Frech, Prosser</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Reference: XF:dtaction-bo
Reference: XF:sun-dtaction</comment>
<comment voter="Prosser">Buffer overflow also affects /usr/dt/bin/dtaction in libDtSvc.a
library in AIX 4.x, but reference for this Sun vulnerability should
only reflect the Sun Bulletin or the CIAC I-032 version of the Sun
Bulletin</comment>
<comment voter="Christey">This is the Same Codebase as CVE-1999-0089, so the two entries
should be merged.</comment>
<comment voter="Frech">Replace sun-dtaction(732) with dtaction-bo(879)</comment>
<comment voter="Baker">Merge with 1999-0089</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0122" seq="1999-0122">
<status>Entry</status>
<desc>Buffer overflow in AIX lchangelv gives root access.</desc>
<refs>
<ref source="BUGTRAQ">Jul21,1999</ref>
<ref source="XF">lchangelv-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0123" seq="1999-0123">
<status>Candidate</status>
<phase date="20000105">Modified</phase>
<desc>Race condition in Linux mailx command allows local users to read user files.</desc>
<refs>
<ref source="XF">linux-mailx</ref>
<ref source="BUGTRAQ">19951222 mailx-5.5 (slackware /bin/mail) security hole</ref>
</refs>
<votes>
<accept count="3">Baker, Frech, Ozancin</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-0124" seq="1999-0124">
<status>Entry</status>
<desc>Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</desc>
<refs>
<ref source="CERT">CA-93:11.UMN.UNIX.gopher.vulnerability</ref>
<ref source="XF">gopher-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0125" seq="1999-0125">
<status>Entry</status>
<desc>Buffer overflow in SGI IRIX mailx program.</desc>
<refs>
<ref source="XF">sgi-mailx-bo</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX">19980605-01-PX</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0126" seq="1999-0126">
<status>Entry</status>
<desc>SGI IRIX buffer overflow in xterm and Xaw allows root access.</desc>
<refs>
<ref source="CERT">VB-98.04.xterm.Xaw</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-010.shtml">J-010</ref>
<ref source="XF">xfree86-xterm-xaw</ref>
<ref source="XF">xfree86-xaw</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0127" seq="1999-0127">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</desc>
<refs>
<ref source="CERT">CA-96.27.hp_sw_install</ref>
<ref source="AUSCERT">AA-96.04</ref>
<ref source="XF">hpux-swinstall</ref>
</refs>
<votes>
<accept count="2">Baker, Prosser</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">(keep current XF: reference, and add)
XF:hpux-sqwmodify</comment>
<comment voter="Christey">Perhaps this should be split, per SF-LOC.</comment>
<comment voter="Christey">CIAC:H-81
http://ciac.llnl.gov/ciac/bulletins/h-81.shtml
HP:HPSBUX9707-064  references CERT:CA-96.27
http://ciac.llnl.gov/ciac/bulletins/h-81.shtml

The original AUSCERT advisory says that the programs &quot;create
files in an insecure manner&quot; and &quot;Exploit details involving
this vulnerability have been made publicly available.&quot; which
leads one to assume that the following original Bugtraq post
provides the details for a standard symlink problem:

BUGTRAQ:19961005 swinst,bug
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419941&amp;w=2</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0128" seq="1999-0128">
<status>Entry</status>
<desc>Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</desc>
<refs>
<ref source="XF">ping-death</ref>
<ref source="CERT">CA-96.26.ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0129" seq="1999-0129">
<status>Entry</status>
<desc>Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</desc>
<refs>
<ref source="CERT">CA-96.25.sendmail_groups</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0130" seq="1999-0130">
<status>Entry</status>
<desc>Local users can start Sendmail in daemon mode and gain root privileges.</desc>
<refs>
<ref source="CERT">CA-96.24.sendmail.daemon.mode</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref>
<ref source="XF">sendmail-daemon-mode</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0131" seq="1999-0131">
<status>Entry</status>
<desc>Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</desc>
<refs>
<ref source="CERT">CA-96.20.sendmail_vul</ref>
<ref source="XF">smtp-875bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0132" seq="1999-0132">
<status>Entry</status>
<desc>Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11723">11723</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0133" seq="1999-0133">
<status>Entry</status>
<desc>fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT">CA-96.18.fm_fls</ref>
<ref source="XF">fmaker-logfile</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0134" seq="1999-0134">
<status>Entry</status>
<desc>vold in Solaris 2.x allows local users to gain root access.</desc>
<refs>
<ref source="XF">sol-voldtmp</ref>
<ref source="CERT">CA-96.17.Solaris_vold_vul</ref>
<ref source="AUSCERT">AL-96.04</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8159">8159</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0135" seq="1999-0135">
<status>Entry</status>
<desc>admintool in Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sun-admintool</ref>
<ref source="CERT">CA-96.16.Solaris_admintool_vul</ref>
<ref source="AUSCERT">AL-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0136" seq="1999-0136">
<status>Entry</status>
<desc>Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sol-KCMSvuln</ref>
<ref source="AUSCERT">AL-96.02</ref>
<ref source="CERT">CA-96.15.Solaris_KCMS_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0137" seq="1999-0137">
<status>Entry</status>
<desc>The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</desc>
<refs>
<ref source="XF">linux-dipbo</ref>
<ref source="CERT">CA-96.13.dip_vul</ref>
<ref source="XF">dip-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0138" seq="1999-0138">
<status>Entry</status>
<desc>The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</desc>
<refs>
<ref source="CERT">CA-96.12.suidperl_vul</ref>
<ref source="XF">sperl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0139" seq="1999-0139">
<status>Entry</status>
<desc>Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</desc>
<refs>
<ref source="XF">sol-mkcookie</ref>
<ref source="RSI">RSI.0012.12-03-98.SOLARIS.MKCOOKIE</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8205">8205</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0140" seq="1999-0140">
<status>Candidate</status>
<phase date="19990630">Proposed</phase>
<desc>Denial of service in RAS/PPTP on NT systems.</desc>
<refs>
</refs>
<votes>
<accept count="1">Hill</accept>
<modify count="2">Frech, Meunier</modify>
<noop count="1">Baker</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Meunier">Add &quot;pptp invalid packet length in header&quot; to distinguish from other
vulnerabilities in RAS/PPTP on NT systems resulting in DOS, that might be
discovered in the future.</comment>
<comment voter="Frech">XF:nt-ras-bo
ONLY IF reference is to MS:MS99-016</comment>
<comment voter="Christey">According to my mappings, this is not the MS:MS99-016 problem
referred to by Andre.  However, I have yet to dig up a
source.</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="CHANGE">[Christey changed vote from REVIEWING to REJECT]</comment>
<comment voter="Christey">This is too general to know which problem is being discussed.
More precise candidates should be created.</comment>
<comment voter="Christey">Consider adding BID:2111</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0141" seq="1999-0141">
<status>Entry</status>
<desc>Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</desc>
<refs>
<ref source="XF">http-java-applet</ref>
<ref source="CERT">CA-96.07.java_bytecode_verifier</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0142" seq="1999-0142">
<status>Entry</status>
<desc>The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</desc>
<refs>
<ref source="CERT">CA-96.05.java_applet_security_mgr</ref>
<ref source="XF">http-java-appletsecmgr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0143" seq="1999-0143">
<status>Entry</status>
<desc>Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</desc>
<refs>
<ref source="CERT">CA-96.03.kerberos_4_key_server</ref>
<ref source="XF">kerberos-bf</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0144" seq="1999-0144">
<status>Candidate</status>
<phase date="20010301">Modified</phase>
<desc>Denial of service in Qmail by specifying a large number of recipients with the RCPT command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319029&amp;w=2">19970612 Re: Denial of service (qmail-smtpd)</ref>
<ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref>
<ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2237">2237</ref>
<ref source="XF" url="http://xforce.iss.net/static/208.php">qmail-rcpt</ref>
</refs>
<votes>
<accept count="4">Baker, Frech, Hill, Meunier</accept>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">DUPE CVE-1999-0418 and CVE-1999-0250?</comment>
<comment voter="Christey">Dan Bernstein, author of Qmail, says that this is not a
vulnerability in qmail because Unix has built-in resource
limits that can restrict the size of a qmail process; other
limits can be specified by the administrator.  See
http://cr.yp.to/qmail/venema.html

Significant discussion of this issue took place on the qmail
list.  The fundamental question appears to be whether 
application software should set its own limits, or rely
on limits set by the parent operating system (in this case,
UNIX).  Also, some people said that the only problem was that
the suggested configuration was not well documented, but this
was refuted by others.

See the following threads at
http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html
&quot;Denial of service (qmail-smtpd)&quot;
&quot;qmail-dos-2.c, another denial of service&quot;
&quot;[PATCH] denial of service&quot;
&quot;just another qmail denial-of-service&quot;
&quot;the UNIX way&quot;
&quot;Time for a reality check&quot;

Also see Bugtraq threads on a different vulnerability that
is related to this topic:
BUGTRAQ:19990903 Web servers / possible DOS Attack / mime header flooding
http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html</comment>
<comment voter="Baker">http://cr.yp.to/qmail/venema.html
Berstein rejects this as a vulnerability, claiming this is a slander campaign by Wietse Venema.
His page states this is not a qmail problem, rather it is a UNIX problem
that many apps can consume all available memory, and that the administrator
is responsible to set limits in the OS, rather than expect applications to
individually prevent memory exhaustion.  CAN 1999-0250 does appear to
be a duplicate of this entry, based on the research I have done so far.
There were two different bugtraq postings, but the second one references
the first, stating that the new exploit uses perl instead of shell scripting
to accomplish the same attack/exploit.</comment>
<comment voter="Baker">http://www.securityfocus.com/archive/1/6970
http://www.securityfocus.com/archive/1/6969
http://cr.yp.to/qmail/venema.html

Should probably reject CVE-1999-0250, and add these references to this
Candidate.</comment>
<comment voter="Baker">http://www.securityfocus.com/bid/2237</comment>
<comment voter="CHANGE">[Baker changed vote from REVIEWING to ACCEPT]</comment>
<comment voter="Christey">qmail-dos-1.c, as published by Wietse Venema (CVE-1999-0250)
in &quot;BUGTRAQ:19970612 Denial of service (qmail-smtpd)&quot;, does not
use any RCPT commands.  Instead, it sends long strings
of &quot;X&quot; characters.  A followup by &quot;super@UFO.ORG&quot; includes
an exploit that claims to do the same thing; however, that
exploit does not send long strings of X characters - it sends
a large number of RCPT commands.  It appears that super@ufo.org
followed up to the wrong message.

NOTE: the ufo.org domain was purchased by another party in
2003, so the current owner is not associated with any
statements by &quot;super@ufo.org&quot; that were made before 2003.

qmail-dos-2.c, as published by Wietse Venema (CVE-1999-0144)
in &quot;BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack&quot;
sends a large number of RCPT commands.

ADDREF BID:2237
ADDREF BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack
ADDREF BUGTRAQ:19970612 Re: Denial of service (qmail-smtpd)

Also see a related thread:
BUGTRAQ:19990308 SMTP server account probing
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100018214316&amp;w=2

This also describes a problem with mail servers not being able
to handle too many &quot;RCPT TO&quot; requests.  A followup message
notes that application-level protection is used in Sendmail
to prevent this:
BUGTRAQ:19990309 Re: SMTP server account probing
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92101584629263&amp;w=2
The person further says, &quot;This attack can easily be
prevented with configuration methods.&quot;</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0145" seq="1999-0145">
<status>Entry</status>
<desc>Sendmail WIZ command enabled, allowing root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref>
<ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0146" seq="1999-0146">
<status>Entry</status>
<desc>The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</desc>
<refs>
<ref source="BUGTRAQ">19970715 Bug CGI campas</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/298">http-cgi-campas(298)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0147" seq="1999-0147">
<status>Entry</status>
<desc>The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</desc>
<refs>
<ref source="XF">http-cgi-glimpse</ref>
<ref source="AUSCERT">AA-97.28</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0148" seq="1999-0148">
<status>Entry</status>
<desc>The handler CGI program in IRIX allows arbitrary command execution.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref>
<ref source="XF">http-sgi-handler</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0149" seq="1999-0149">
<status>Entry</status>
<desc>The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970420 IRIX 6.x /cgi-bin/wrap bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref>
<ref source="OSVDB" url="http://www.osvdb.org/247">247</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/290">http-sgi-wrap(290)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0150" seq="1999-0150">
<status>Entry</status>
<desc>The Perl fingerd program allows arbitrary command execution from remote users.</desc>
<refs>
<ref source="XF">perl-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0151" seq="1999-0151">
<status>Entry</status>
<desc>The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</desc>
<refs>
<ref source="CERT">CA-95.07a.REVISED.satan.vul</ref>
<ref source="CERT">CA-95.06.satan.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0152" seq="1999-0152">
<status>Entry</status>
<desc>The DG/UX finger daemon allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19970811 dgux in.fingerd vulnerability</ref>
<ref source="XF">dgux-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0153" seq="1999-0153">
<status>Entry</status>
<desc>Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</desc>
<refs>
<ref source="XF">win-oob</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1666">1666</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0154" seq="1999-0154">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.</desc>
<refs>
<ref source="MSKB">Q163485</ref>
<ref source="MSKB">Q164059</ref>
<ref source="BUGTRAQ">19970220 ! [ADVISORY] Major Security Hole in MS ASP</ref>
<ref source="XF">http-iis-aspdot</ref>
<ref source="XF">http-iis-aspsource</ref>
</refs>
<votes>
<accept count="4">Foat, Frech, Stracener, Wall</accept>
<noop count="3">Baker, Christey, Cole</noop>
</votes>
<comments>
<comment voter="Christey">This is the precursor to the problem that is identified in
CVE-1999-0253.  </comment>
<comment voter="Christey">CIAC:H-48
URL:http://ciac.llnl.gov/ciac/bulletins/h-48.shtml</comment>
<comment voter="CHANGE">[Foat changed vote from NOOP to ACCEPT]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0155" seq="1999-0155">
<status>Entry</status>
<desc>The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</desc>
<refs>
<ref source="XF">gscript-dsafer</ref>
<ref source="CERT">CA-95.10.ghostscript</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0156" seq="1999-0156">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>wu-ftpd FTP daemon allows any user and password combination.</desc>
<refs>
<ref source="XF">ftp-pwless</ref>
</refs>
<votes>
<accept count="2">Northcutt, Shostack</accept>
<noop count="1">Baker</noop>
<recast count="1">Frech</recast>
<reviewing count="2">Christey, Prosser</reviewing>
</votes>
<comments>
<comment voter="Prosser">but so far can find no reference to this one</comment>
<comment voter="Frech">Our records indicate that this does not necessarly affect just wu-ftp (ie,
also affects IIS FTP server).</comment>
<comment voter="Christey">The references for XF:ftp-pwless are not specific enough,
e.g. in terms of version numbers.  Perhaps this candidate
should be rejected due to insufficient information.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0157" seq="1999-0157">
<status>Entry</status>
<desc>Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/nifrag.shtml</ref>
<ref source="XF">cisco-fragmented-attacks</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1097">1097</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0158" seq="1999-0158">
<status>Entry</status>
<desc>Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml">20010913 Cisco PIX Firewall Manager File Exposure</ref>
<ref source="XF">cisco-pix-file-exposure</ref>
<ref source="OSVDB" url="http://www.osvdb.org/685">685</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0159" seq="1999-0159">
<status>Entry</status>
<desc>Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/ioslogin-pub.shtml</ref>
<ref source="XF">cisco-ios-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0160" seq="1999-0160">
<status>Entry</status>
<desc>Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</desc>
<refs>
<ref source="CISCO">19971001 Vulnerabilities in Cisco CHAP Authentication</ref>
<ref source="CIAC">I-002A</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1099">1099</ref>
<ref source="XF">cisco-chap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0161" seq="1999-0161">
<status>Entry</status>
<desc>In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/707/1.html</ref>
<ref source="XF">cisco-acl-tacacs</ref>
<ref source="OSVDB" url="http://www.osvdb.org/797">797</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0162" seq="1999-0162">
<status>Entry</status>
<desc>The &quot;established&quot; keyword in some Cisco IOS software allowed an attacker to bypass filtering.</desc>
<refs>
<ref source="CISCO">19950601 &quot;Established&quot; Keyword May Allow Packets to Bypass Filter</ref>
<ref source="XF">cisco-acl-established</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0163" seq="1999-0163">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>In older versions of Sendmail, an attacker could use a pipe character to execute root commands.</desc>
<refs>
<ref source="XF">smtp-pipe</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<modify count="1">Prosser</modify>
<noop count="2">Baker, Christey</noop>
<recast count="1">Shostack</recast>
</votes>
<comments>
<comment voter="Shostack">there was a 'To: |' and a 'From: |' attack, which I
think are seperate.</comment>
<comment voter="Prosser">older vulnerability, but one additional reference is-
The Ultimate Sendmail Hole List by Markus H&#252;bner @
bau2.uibk.ac.at/matic/buglist.htm
'|PROGRAM '</comment>
<comment voter="Christey">Description needs to be more specific to distinguish between
this and CVE-1999-0203, as alluded to by Adam Shostack</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0164" seq="1999-0164">
<status>Entry</status>
<desc>A race condition in the Solaris ps command allows an attacker to overwrite critical files.</desc>
<refs>
<ref source="XF">sol-pstmprace</ref>
<ref source="AUSCERT">AA-95.07</ref>
<ref source="CERT">CA-95.09.Solaris.ps.vul</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8346">8346</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0165" seq="1999-0165">
<status>Candidate</status>
<phase date="20040811">Modified</phase>
<desc>NFS cache poisoning.</desc>
<refs>
<ref source="XF">nfs-cache</ref>
</refs>
<votes>
<accept count="3">Baker, Frech, Northcutt</accept>
<modify count="1">Shostack</modify>
<noop count="1">Prosser</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Shostack">need more data</comment>
<comment voter="Christey">need more refs</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0166" seq="1999-0166">
<status>Entry</status>
<desc>NFS allows users to use a &quot;cd ..&quot; command to access other directories besides the exported file system.</desc>
<refs>
<ref source="XF">nfs-cd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0167" seq="1999-0167">
<status>Entry</status>
<desc>In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</desc>
<refs>
<ref source="XF">nfs-guess</ref>
<ref source="CERT">CA-91.21.SunOS.NFS.Jumbo.and.fsirand</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0168" seq="1999-0168">
<status>Entry</status>
<desc>The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</desc>
<refs>
<ref source="XF">nfs-portmap</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0169" seq="1999-0169">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>NFS allows attackers to read and write any file on the system by specifying a false UID.</desc>
<refs>
<ref source="XF">nfs-uid</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<modify count="1">Baker</modify>
<reject count="1">Shostack</reject>
</votes>
<comments>
<comment voter="Shostack">this is not a vulnerability but a design feature.</comment>
<comment voter="Baker">Maybe we should reword it so that it is clear that this was a problem to something like:

&quot;A remote attacker could read/write files to the system with root-level permissions on NFS servers that fail to properly check the UID.&quot;</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0170" seq="1999-0170">
<status>Entry</status>
<desc>Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</desc>
<refs>
<ref source="XF">nfs-ultrix</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0171" seq="1999-0171">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Denial of service in syslog by sending it a large number of superfluous messages.</desc>
<refs>
<ref source="XF">syslog-flood</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<noop count="1">Baker</noop>
<reject count="2">Christey, Shostack</reject>
</votes>
<comments>
<comment voter="Shostack">design issue, not a vulnerability.  Alternately, add:
DOS on server by opening a large number of telnet sessions..</comment>
<comment voter="Christey">Duplicate of CVE-1999-0566</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0172" seq="1999-0172">
<status>Entry</status>
<desc>FormMail CGI program allows remote execution of commands.</desc>
<refs>
<ref source="XF">http-cgi-formmail-exe</ref>
<ref source="BUGTRAQ">Aug02,1995</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0173" seq="1999-0173">
<status>Entry</status>
<desc>FormMail CGI program can be used by web servers other than the host server that the program resides on.</desc>
<refs>
<ref source="XF">http-cgi-formmail-use</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0174" seq="1999-0174">
<status>Entry</status>
<desc>The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970208 view-source</ref>
<ref source="XF">http-cgi-viewsrc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0175" seq="1999-0175">
<status>Entry</status>
<desc>The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</desc>
<refs>
<ref source="XF">http-nov-convert</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0176" seq="1999-0176">
<status>Entry</status>
<desc>The Webgais program allows a remote user to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ">Jul10,1997</ref>
<ref source="XF">http-webgais-query</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0177" seq="1999-0177">
<status>Entry</status>
<desc>The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</desc>
<refs>
<ref source="NTBUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="NTBUGTRAQ">19970905 Re: FW: [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="BUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="XF">http-website-uploader</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0178" seq="1999-0178">
<status>Entry</status>
<desc>Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8">8</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0179" seq="1999-0179">
<status>Entry</status>
<desc>Windows NT crashes or locks up when a Samba client executes a &quot;cd ..&quot; command on a file share.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q140818">Q140818</ref>
<ref source="XF">nt-samba-dotdot</ref>
<ref source="XF">nt-351</ref>
<ref source="XF">nt-35</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0180" seq="1999-0180">
<status>Entry</status>
<desc>in.rshd allows users to login with a NULL username and execute commands.</desc>
<refs>
<ref source="XF">rsh-null</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0181" seq="1999-0181">
<status>Entry</status>
<desc>The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</desc>
<refs>
<ref source="XF">walld</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0182" seq="1999-0182">
<status>Entry</status>
<desc>Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref>
<ref source="CERT">VB-97.10.samba</ref>
<ref source="XF">nt-samba-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0183" seq="1999-0183">
<status>Entry</status>
<desc>Linux implementations of TFTP would allow access to files outside the restricted directory.</desc>
<refs>
<ref source="XF">linux-tftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0184" seq="1999-0184">
<status>Entry</status>
<desc>When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</desc>
<refs>
<ref source="XF">dns-updates</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0185" seq="1999-0185">
<status>Entry</status>
<desc>In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref>
<ref source="XF">sun-ftpd/logind</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0186" seq="1999-0186">
<status>Candidate</status>
<phase date="20071119">Modified</phase>
<desc>In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.</desc>
<refs>
<ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm</ref>
<ref source="SUN">00178</ref>
<ref source="XF">snmp-backdoor-access</ref>
</refs>
<votes>
<accept count="2">Baker, Dik</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Change XF:snmp-backdoor-access to XF:sol-hidden-commstr
Add ISS:Hidden Community String in SNMP Implementation</comment>
<comment voter="Christey">What is the proper level of abstraction to use here?  Should
we have a separate entry for each different default community
string?  See:
http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and
http://cve.mitre.org/Board_Sponsors/archives/msg00250.html
http://cve.mitre.org/Board_Sponsors/archives/msg00251.html

Until the associated content decisions have been approved
by the Editorial Board, this candidate cannot be accepted
for inclusion in CVE.</comment>
<comment voter="Christey">ADDREF BID:177</comment>
<comment voter="Christey">ISS:19981102 Hidden community string in SNMP implementation
http://xforce.iss.net/alerts/advise11.php

Change description to include &quot;hidden&quot;</comment>
<comment voter="Christey">XF:snmp-backdoor-access is missing.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0187" seq="1999-0187">
<status>Candidate</status>
<phase date="20050204">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0022.  Reason: This candidate is a duplicate of CVE-1999-0022.  Notes: All CVE users should reference CVE-1999-0022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<accept count="2">Hill, Northcutt</accept>
<recast count="3">Baker, Frech, Prosser</recast>
<reject count="1">Dik</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Prosser">The Sun Patches in Ref roll-up fixes for an earlier BO in
rdist lookup( )(ref CERT 96.14)as well as the BO in rdist function expstr()
(ref CERT 97-23) and various vendor bulletins.  However both of these rdist
BO's affect many more OSs than just Sun, i.e., BSD/OS 2.1, DEC OSF's, AIX,
FreeBSD, SCO, SGI, etc.  Believe this falls into the SF-codebase content
decision</comment>
<comment voter="Frech">XF:rdist-bo (error msg formation)
XF:rdist-bo2 (execute code)
XF:rdist-bo3 (execute user-created code)
XF:rdist-sept97 (root from local)</comment>
<comment voter="Christey">Duplicate of CVE-1999-0022 (SUN:00179 is referenced in
CERT:CA-97.23.rdist), but as Mike and Andre noted, there
are multiple flaws here, so a RECAST may be necessary.</comment>
<comment voter="Dik">As currently phrasedm thissa duplicate of CVE-1999-0022</comment>
<comment voter="Baker">Based on our new philosophy, this should be recast/merged or re-described.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0188" seq="1999-0188">
<status>Entry</status>
<desc>The passwd command in Solaris can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182">00182</ref>
<ref source="XF">sun-passwd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0189" seq="1999-0189">
<status>Entry</status>
<desc>Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</desc>
<refs>
<ref source="NAI">NAI-15</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref>
<ref source="XF">rpc-32771</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0190" seq="1999-0190">
<status>Entry</status>
<desc>Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167">00167</ref>
<ref source="XF">sun-rpcbind</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0191" seq="1999-0191">
<status>Entry</status>
<desc>IIS newdsn.exe CGI script allows remote users to overwrite files.</desc>
<refs>
<ref source="XF">http-cgi-newdsn</ref>
<ref source="OSVDB" url="http://www.osvdb.org/275">275</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0192" seq="1999-0192">
<status>Entry</status>
<desc>Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</desc>
<refs>
<ref source="SNI">SNI-20</ref>
<ref source="XF">bsd-tel-tgetent</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0193" seq="1999-0193">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.</desc>
<refs>
</refs>
<votes>
<accept count="5">Bishop, Cole, Northcutt, Ozancin, Shostack</accept>
<modify count="2">Baker, Blake</modify>
<noop count="4">Armstrong, Frech, Landfield, Wall</noop>
<reviewing count="2">Christey, Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">possibly XF:ascend-kill
I can't find a reference that lists both routers in the same reference.</comment>
<comment voter="Wall">Comment:  There is a reference about the zero length TCP option in BugTraq on
Feb 5, 1999
and it mentions Cisco, but not directly Ascend or 3Com.  CIAC Advisory I-038
mentions
vulnerabilities in Ascend, but does not mention TCP.  CIAC Advisory I-052
mentions
3Com vulnerabilities, but not TCP.  Too confusing withour better references.</comment>
<comment voter="Landfield">What are the references for this ? I cannot find a means to check it out.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to NOOP]</comment>
<comment voter="Frech">Cannot reconcile to our database without further references.</comment>
<comment voter="Blake">I'm with Andre.  I only remember and can find reference to the Ascend
issue.  Do we have a refernce to the 3Coms?  If not, that should be
removed from the description.</comment>
<comment voter="Baker">http://xforce.iss.net/static/614.php	Misc Defensive Info
http://www.securityfocus.com/archive/1/5682	Misc Offensive Info
http://www.securityfocus.com/archive/1/5647	Misc Defensive Info
http://www.securityfocus.com/archive/1/5640	Misc Defensive Info</comment>
<comment voter="CHANGE">[Armstrong changed vote from REVIEWING to NOOP]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0194" seq="1999-0194">
<status>Entry</status>
<desc>Denial of service in in.comsat allows attackers to generate messages.</desc>
<refs>
<ref source="XF">comsat</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0195" seq="1999-0195">
<status>Candidate</status>
<phase date="19991130">Modified</phase>
<desc>Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.</desc>
<refs>
<ref source="BUGTRAQ">19990128 rpcbind: deceive, enveigle and obfuscate</ref>
</refs>
<votes>
<accept count="2">Balinsky, Shostack</accept>
<modify count="1">Frech</modify>
<noop count="3">Baker, Northcutt, Wall</noop>
<reviewing count="2">Christey, Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:rpcbind-spoof</comment>
<comment voter="Christey">CVE-1999-0195 = CVE-1999-0461 ?
If this is approved over CVE-1999-0461, make sure it gets
XF:pmap-sset</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0196" seq="1999-0196">
<status>Entry</status>
<desc>websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</desc>
<refs>
<ref source="BUGTRAQ">19970704 Vulnerability in websendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref>
<ref source="OSVDB" url="http://www.osvdb.org/237">237</ref>
<ref source="XF">http-webgais-smail</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0197" seq="1999-0197">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>finger 0@host on some systems may print information on some user accounts.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Shostack</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Shostack">fingerd may respond to 'finger 0@host' with account info</comment>
<comment voter="Frech">Need more reference to establish this 'exposure'.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:finger-unused-accounts(8378)
We're entering it into our database solely to track
competition. The only references seem to be product listings:
http://hq.mcafeeasap.com/vulnerabilities/vuln_data/1000.asp (1002
Finger 0@host check)
http://www.ipnsa.com/ipnsa_vuln.htm?step=1000 (Finger 0@host check)
http://cgi.nessus.org/plugins/dump.php3?id=10069 (Finger zero at host
feature)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0198" seq="1999-0198">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>finger .@host on some systems may print information on some user accounts.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Shostack</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Shostack">as above</comment>
<comment voter="Frech">Need more reference to establish this 'exposure'.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:finger-unused-accounts(8378)
We're entering it into our database solely to track
competition. The only references seem to be product listings:
http://hq.mcafeeasap.com/vulnerabilities/vuln_data/1000.asp (1004
Finger .@target-host check)
http://www.ipnsa.com/ipnsa_vuln.htm?step=1000 (Finger .@target-host
check )
http://cgi.nessus.org/plugins/dump.php3?id=10072 (Finger dot at host
feature)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0200" seq="1999-0200">
<status>Candidate</status>
<phase date="19991130">Modified</phase>
<desc>Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.</desc>
<refs>
<ref source="MSKB">Q137853</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Shostack</modify>
<noop count="2">Northcutt, Wall</noop>
<reject count="1">Christey</reject>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Shostack">WFTP is not sufficient; is this wu-, ws-, war-, or another?</comment>
<comment voter="Frech">Other have mentioned this before, but it may be WU-FTP.
POSSIBLY XF:ftp-exec; does this have to do with the Site Exec allowing root
access without anon FTP or a regular account?
POSSIBLY XF:wu-ftpd-exec;same as above conditions, but instead from a
non-anon FTP account and gain root privs.</comment>
<comment voter="Christey">added MSKB reference</comment>
<comment voter="CHANGE">[Christey changed vote from REVOTE to REJECT]</comment>
<comment voter="Christey">The MSKB article may have confused things even more.  There
were reports of problems in a Windows-based FTP server called
WFTP (http://www.wftpd.com/) that is not a Microsft FTP
server.  It's best to just kill this candidate where it
stands and start fresh.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0201" seq="1999-0201">
<status>Entry</status>
<desc>A quote cwd command on FTP servers can reveal the full path of the home directory of the &quot;ftp&quot; user.</desc>
<refs>
<ref source="XF">ftp-home</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0202" seq="1999-0202">
<status>Entry</status>
<desc>The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</desc>
<refs>
<ref source="XF">ftp-exectar</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0203" seq="1999-0203">
<status>Entry</status>
<desc>In Sendmail, attackers can gain root privileges via SMTP by specifying an improper &quot;mail from&quot; address and an invalid &quot;rcpt to&quot; address that would cause the mail to bounce to a program.</desc>
<refs>
<ref source="CERT">CA-95.08</ref>
<ref source="CIAC">E-03</ref>
<ref source="XF">smtp-sendmail-version5</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0204" seq="1999-0204">
<status>Entry</status>
<desc>Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</desc>
<refs>
<ref source="XF">ident-bo</ref>
<ref source="CIAC">F-13</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0205" seq="1999-0205">
<status>Candidate</status>
<phase date="19990925">Modified</phase>
<desc>Denial of service in Sendmail 8.6.11 and 8.6.12.</desc>
<refs>
<ref source="BUGTRAQ">19990708 SM 8.6.12</ref>
</refs>
<votes>
<accept count="2">Hill, Northcutt</accept>
<modify count="2">Frech, Prosser</modify>
<noop count="1">Baker</noop>
<reviewing count="2">Christey, Ozancin</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:sendmail-alias-dos</comment>
<comment voter="Prosser">additional source
Bugtraq
&quot;Re:  SM 8.6.12&quot;
http://www.securityfocus.com</comment>
<comment voter="Christey">The Bugtraq thread does not provide any proof, including a
comment by Eric Allman that he hadn't been provided any
details either.

See http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1995-07-8&amp;thread=199507131402.KAA02492@bedbugs.net.ohio-state.edu
for the thread.</comment>
<comment voter="Christey">Change Bugtraq reference date to 19950708.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0206" seq="1999-0206">
<status>Entry</status>
<desc>MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</desc>
<refs>
<ref source="XF">sendmail-mime-bo</ref>
<ref source="AUSCERT">AA-96.06a</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0207" seq="1999-0207">
<status>Entry</status>
<desc>Remote attacker can execute commands through Majordomo using the Reply-To field and a &quot;lists&quot; command.</desc>
<refs>
<ref source="XF">majordomo-exe</ref>
<ref source="CERT">CA-94.11.majordomo.vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0208" seq="1999-0208">
<status>Entry</status>
<desc>rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="XF">rpc-update</ref>
<ref source="CERT">CA-95.17.rpc.ypupdated.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0209" seq="1999-0209">
<status>Entry</status>
<desc>The SunView (SunTools) selection_svc facility allows remote users to read files.</desc>
<refs>
<ref source="CERT">CA-90.05.sunselection.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref>
<ref source="XF">selsvc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0210" seq="1999-0210">
<status>Entry</status>
<desc>Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104">HPSBUX9910-104</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/235">235</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0211" seq="1999-0211">
<status>Entry</status>
<desc>Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</desc>
<refs>
<ref source="CERT">CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0212" seq="1999-0212">
<status>Entry</status>
<desc>Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/168">00168</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-048.shtml">I-048</ref>
<ref source="XF">sun-mountd</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0213" seq="1999-0213">
<status>Candidate</status>
<phase date="20001009">Modified</phase>
<desc>libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.</desc>
<refs>
<ref source="XF">sun-libnsl</ref>
<ref source="SUNBUG">4305859</ref>
</refs>
<votes>
<accept count="6">Blake, Cole, Dik, Hill, Landfield, Ozancin</accept>
<modify count="3">Baker, Frech, Levy</modify>
<noop count="4">Armstrong, Bishop, Meunier, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:sun-libnsl</comment>
<comment voter="Dik">Sun bug #4305859</comment>
<comment voter="Baker">http://xforce.iss.net/static/1204.php	Misc Defensive Info
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172&amp;type=0&amp;nav=sec.sba	Vendor Info
http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/A1050E354364BF498525680F0077E414/$file/ERS-OAR-E01-1998_074_1.txt	Vendor Info
http://www.securityfocus.com/archive/1/9749	Misc Defensive Info</comment>
<comment voter="Christey">I don't think this is the bug that everyone thinks it is.
This candidate came from CyberCop Scanner 2.4/2.5, which
only reports this as a DoS problem.  If SUN:00172 is an
advisory for this, then it may be a duplicate of
CVE-1999-0055.  There appears to be overlap with other
references as well.  HOWEVER, this particular one deals with a
DoS in rpcbind - which isn't mentioned in the sources for
CVE-1999-0055.</comment>
<comment voter="Levy">BID 148</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0214" seq="1999-0214">
<status>Entry</status>
<desc>Denial of service by sending forged ICMP unreachable packets.</desc>
<refs>
<ref source="XF">icmp-unreachable</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0215" seq="1999-0215">
<status>Entry</status>
<desc>Routed allows attackers to append data to files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX">19981004-01-PX</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-012.shtml">J-012</ref>
<ref source="XF">ripapp</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0216" seq="1999-0216">
<status>Candidate</status>
<phase date="19991203">Modified</phase>
<desc>Denial of service of inetd on Linux through SYN and RST packets.</desc>
<refs>
<ref source="BUGTRAQ">19971130 Linux inetd..</ref>
<ref source="XF">linux-inetd-dos</ref>
<ref source="HP">HPSBUX9803-077</ref>
<ref source="XF">hp-inetd</ref>
</refs>
<votes>
<accept count="1">Hill</accept>
<modify count="2">Baker, Frech</modify>
<recast count="1">Meunier</recast>
</votes>
<comments>
<comment voter="Meunier">The location of the vulnerability, whether in the Linux kernel or the
application, is debatable.  Any program making the same (reasonnable)
assumption is vulnerable, i.e., implements the same vulnerability:
&quot;Assumption that TCP-three-way handshake is complete after calling Linux
kernel function accept(), which returns socket after getting SYN.   Result
is process death by SIGPIPE&quot;
Moreover, whether it results in DOS (to third parties) depends on the
process that made the assumption.
I think that the present entry should be split, one entry for every
application that implements the vulnerability (really describing threat
instances, which is what other people think about when we talk about
vulnerabilities), and one entry for the Linux kernel that allows the
vulnerability to happen.</comment>
<comment voter="Frech">XF:hp-inetd
XF:linux-inetd-dos</comment>
<comment voter="Baker">Since we have an hpux bulletin, the description should not specifically say Linux, should it?  It applies to mulitple OS and should be likely either modified, or in extreme case, recast</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0217" seq="1999-0217">
<status>Entry</status>
<desc>Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</desc>
<refs>
<ref source="XF">udp-bomb</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0218" seq="1999-0218">
<status>Entry</status>
<desc>Livingston portmaster machines could be rebooted via a series of commands.</desc>
<refs>
<ref source="XF">portmaster-reboot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0219" seq="1999-0219">
<status>Entry</status>
<desc>Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="BUGTRAQ">19990909 Exploit: Serv-U Ver2.5 FTPd Win9x/NT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/205">ftp-servu(205)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0220" seq="1999-0220">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Attackers can do a denial of service of IRC by crashing the server.</desc>
<refs>
</refs>
<votes>
<noop count="2">Baker, Northcutt</noop>
<reject count="2">Christey, Frech</reject>
</votes>
<comments>
<comment voter="Frech">Would reconsider if any references were available.</comment>
<comment voter="Christey">No references available, combined with extremely vague
description, equals REJECT.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0221" seq="1999-0221">
<status>Entry</status>
<desc>Denial of service of Ascend routers through port 150 (remote administration).</desc>
<refs>
<ref source="XF">ascend-150-kill</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0222" seq="1999-0222">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="3">Frech, Levy, Shostack</modify>
<noop count="3">Balinsky, Northcutt, Wall</noop>
<recast count="1">Ziese</recast>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Shostack">I follow cisco announcements and problems pretty closely, and haven't
seen this.  Source?</comment>
<comment voter="Frech">XF:cisco-web-crash</comment>
<comment voter="Christey">XF:cisco-web-crash has no additional references.  I can't find
any references in Bugtraq or Cisco either.  This bug is
supposedly tested by at least one security product, but that
product's database doesn't have any references either.  So
a question becomes, how did it make it into at least two
security companies' databases?</comment>
<comment voter="Levy">BUGTGRAQ: http://www.securityfocus.com/archive/1/60159
BID 1154</comment>
<comment voter="Ziese">The vulnerability is addressed by a vendor acknowledgement.  This one, if
recast to reflect that &quot;...after using a long url...&quot; should be replaced
with
&quot;...A defect in multiple releases of Cisco IOS software will cause a Cisco
router or switch to halt and reload if the IOS HTTP service is enabled,
browsing to &quot;http://router-ip/anytext?/&quot; is attempted, and the enable
password is supplied when requested. This defect can be exploited to produce
a denial of service (DoS) attack.&quot;
Then I can accept this and mark it as &quot;Verfied by my Company&quot;.  If it can't
be recast because this (long uri) is diffferent then our release (special
url construction).</comment>
<comment voter="CHANGE">[Christey changed vote from REVIEWING to REJECT]</comment>
<comment voter="Christey">Elias Levy's suggested reference is CVE-2000-0380.
I don't think that Kevin's description is really addressing
this either.  The lack of references and a specific
description make this candidate unusable, so it should be
rejected.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0223" seq="1999-0223">
<status>Entry</status>
<desc>Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.</desc>
<refs>
<ref source="BUGTRAQ">19961109 Syslogd and Solaris 2.4</ref>
<ref source="SUNBUG">1249320</ref>
<ref source="CONFIRM" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches">http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches</ref>
<ref source="XF">sol-syslogd-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1878">1878</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0224" seq="1999-0224">
<status>Entry</status>
<desc>Denial of service in Windows NT messenger service through a long username.</desc>
<refs>
<ref source="XF">nt-messenger</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0225" seq="1999-0225">
<status>Entry</status>
<desc>Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp">19980214 Windows NT Logon Denial of Service</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=180963">Q180963</ref>
<ref source="XF">nt-logondos</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0226" seq="1999-0226">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Christey">Too general, and no references.</comment>
<comment voter="Frech">XF:nt-frag(528)
See reference from BugTraq Mailing List, &quot;A New Fragmentation Attack&quot; at
http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1997-07-8&amp;ms
g=Pine.SUN.3.94.970710054440.11707A-100000@dfw.dfw.net</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0227" seq="1999-0227">
<status>Entry</status>
<desc>Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154087">Q154087</ref>
<ref source="XF">nt-lsass-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0228" seq="1999-0228">
<status>Entry</status>
<desc>Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</desc>
<refs>
<ref source="XF">nt-rpc-ver</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q162567">Q162567</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0229" seq="1999-0229">
<status>Candidate</status>
<phase date="19991228">Modified</phase>
<desc>Denial of service in Windows NT IIS server using ..\..</desc>
<refs>
<ref source="MSKB">Q115052</ref>
</refs>
<votes>
<accept count="2">Baker, Shostack</accept>
<modify count="2">Frech, Wall</modify>
<noop count="1">Northcutt</noop>
<reject count="1">Christey</reject>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Wall">Denial of service in Windows NT IIS Server 1.0 using ..\...
Source: Microsoft Knowledge Base Article Q115052 - IIS Server.</comment>
<comment voter="Frech">XF:http-dotdot (not necessarily IIS?)</comment>
<comment voter="Christey">DELREF XF:http-dotdot - it deals with a read/access dot dot
problem.</comment>
<comment voter="Christey">This actually looks like XF:iis-dot-dot-crash(1638)
http://xforce.iss.net/static/1638.php
If so, include the version number (2.0)
</comment>
<comment voter="CHANGE">[Christey changed vote from REVOTE to REJECT]</comment>
<comment voter="Christey">Bill Wall intended to suggest Q155052, but the affected
IIS version there is 1.0; the effect is to read files,
so this sounds like a directory traversal problem,
instead of an inability to process certain strings.

As a result, this candidate is too general, since it could
apply to 2 different problems, so it should be REJECTed.</comment>
<comment voter="Christey">Consider adding BID:2218</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0230" seq="1999-0230">
<status>Entry</status>
<desc>Buffer overflow in Cisco 7xx routers through the telnet service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/pwbuf-pub.shtml</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1102">1102</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0231" seq="1999-0231">
<status>Candidate</status>
<phase date="19991207">Modified</phase>
<desc>Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.</desc>
<refs>
<ref source="BUGTRAQ">19990317 Re: SLMail 2.6 DoS - Imail also</ref>
</refs>
<votes>
<accept count="2">Baker, Levy</accept>
<noop count="3">Christey, Landfield, Northcutt</noop>
<recast count="1">Frech</recast>
<reviewing count="1">Ozancin</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:slmail-vrfyexpn-overflow (for Slmail v3.2 and below)
XF:smtp-vrfy-bo (many mail packages)</comment>
<comment voter="Northcutt">(There is no way I will have access to these systems)</comment>
<comment voter="Christey">Some sources report that VRFY and EXPN are both affected.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0232" seq="1999-0232">
<status>Candidate</status>
<phase date="19991220">Modified</phase>
<desc>Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</desc>
<refs>
</refs>
<votes>
<accept count="2">Hill, Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Prosser</noop>
<reject count="1">Baker</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Unable to provide a match due to vague/insufficient description/references.
Possible matches are:
XF:ftp-ncsa (probably not, considering you've mentioned the webserver.)
XF:http-ncsa-longurl (highest probability)</comment>
<comment voter="Christey">CVE-1999-0235 is the one associated with XF:http-ncsa-longurl
More research is necessary for this one.</comment>
<comment voter="Baker">Since this has no references at all, and is vague and we have a
CAN for the most likely issue, we should kill this one</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0233" seq="1999-0233">
<status>Entry</status>
<desc>IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q148188">Q148188</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q155056">Q155056</ref>
<ref source="XF">http-iis-cmd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0234" seq="1999-0234">
<status>Entry</status>
<desc>Bash treats any character with a value of 255 as a command separator.</desc>
<refs>
<ref source="XF">bash-cmd</ref>
<ref source="CERT">CA-96.22.bash_vuls</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0235" seq="1999-0235">
<status>Candidate</status>
<phase date="19991220">Modified</phase>
<desc>Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</desc>
<refs>
<ref source="CERT">CA-95:04</ref>
<ref source="CIAC">F-11</ref>
</refs>
<votes>
<accept count="3">Hill, Northcutt, Prosser</accept>
<modify count="1">Frech</modify>
<reject count="2">Baker, Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:http-ncsa-longurl</comment>
<comment voter="Christey">CVE-1999-0235 has the same ref's as CVE-1999-0267</comment>
<comment voter="Baker">Not to mention, the X-force listings of http-ncsa-longurl and http-port both
refer to the same problem.  This should be rejected as 1999-0267 is the same problem.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0236" seq="1999-0236">
<status>Entry</status>
<desc>ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</desc>
<refs>
<ref source="XF">http-scriptalias</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0237" seq="1999-0237">
<status>Entry</status>
<desc>Remote execution of arbitrary commands through Guestbook CGI program.</desc>
<refs>
<ref source="XF">http-cgi-guestbook</ref>
<ref source="CERT">VB-97.02</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0238" seq="1999-0238">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>php.cgi allows attackers to read any file on the system.</desc>
<refs>
<ref source="XF">http-cgi-phpfileread</ref>
</refs>
<votes>
<accept count="5">Baker, Collins, Frech, Northcutt, Prosser</accept>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Prosser">additional source
AUSCERT External Security Bulletin ESB-97.047
http://www.auscert.org.au</comment>
<comment voter="Christey">ADDREF BUGTRAQ:19970416 Update on PHP/FI hole
URL:http://www.dataguard.no/bugtraq/1997_2/0069.html
The attacker specifies the filename as an argument to the
program.
Add &quot;PHP/FI&quot; to description to facilitate search.
AUSCERT URL is ftp://ftp.auscert.org.au/pub/auscert/ESB/ESB-97.047</comment>
<comment voter="Christey">Consider adding BID:2250</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0239" seq="1999-0239">
<status>Entry</status>
<desc>Netscape FastTrack Web server lists files when a lowercase &quot;get&quot; command is used instead of an uppercase GET.</desc>
<refs>
<ref source="XF">fastrack-get-directory-list</ref>
<ref source="OSVDB" url="http://www.osvdb.org/122">122</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0240" seq="1999-0240">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<noop count="1">Baker</noop>
<reject count="1">Frech</reject>
</votes>
<comments>
<comment voter="Frech">Would reconsider if any references were available.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0241" seq="1999-0241">
<status>Candidate</status>
<phase date="19990925">Modified</phase>
<desc>Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.</desc>
<refs>
<ref source="XF">http-xguess-cookie</ref>
</refs>
<votes>
<accept count="3">Hill, Northcutt, Proctor</accept>
<modify count="2">Frech, Prosser</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Also add to references:
XF:sol-mkcookie</comment>
<comment voter="Prosser">additional source
Bugtraq
&quot;X11 cookie hijacker&quot;
http://www.securityfocus.com</comment>
<comment voter="Christey">The cookie hijacker thread has to do with stealing cookies
through a file with bad permissions.  I'm not sure the
X-Force reference identifies this problem either.</comment>
<comment voter="Christey">CIAC:G-04
URL:http://ciac.llnl.gov/ciac/bulletins/g-04.shtml
SGI:19960601-01-I
URL:ftp://patches.sgi.com/support/free/security/advisories/19960601-01-I
CERT:VB-95:08</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0242" seq="1999-0242">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.</desc>
<refs>
<ref source="BUGTRAQ">19951222 mailx-5.5 (slackware /bin/mail) security hole</ref>
<ref source="XF">linux-pop3d</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="4">Christey, Northcutt, Shostack, Wall</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">Ambiguous description: need more detail. Possibly:
XF:linux-pop3d (mktemp() leads to reading e-mail)</comment>
<comment voter="Christey">At first glance this might look like CVE-1999-0123 or
CVE-1999-0125, however this particular candidate arises out
of a brief mention of the problem in a larger posting which
discusses CVE-1999-0123 (which may be the same bug as
CVE-1999-0125).  See the following phrase in the Bugtraq
post: &quot;one such example of this is in.pop3d&quot;

However, the original source of this candidate's description
explicitly mentions shadowed passwords, though it has no
references to help out here.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0243" seq="1999-0243">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Linux cfingerd could be exploited to gain root access.</desc>
<refs>
</refs>
<votes>
<accept count="1">Shostack</accept>
<noop count="4">Baker, Levy, Northcutt, Wall</noop>
<reject count="2">Christey, Frech</reject>
</votes>
<comments>
<comment voter="Christey">This has no sources; neither does the original database that
this entry came from.  It's a likely duplicate of 
CVE-1999-0813.</comment>
<comment voter="Frech">I disagree on the dupe; see Linux-Security Mailing List,
&quot;[linux-security] Cfinger (Yet more :)&quot; at
http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as
if v1.2.3 is vulnerable, perhaps 1.3.0 also. CVE-1999-0813 pertains
to 1.4.x and below and shows up two years later.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to REJECT]</comment>
<comment voter="Frech">If the reference I previously supplied is correct, then
it appears as if the poster modified the source using authorized 
access to make it vulnerable. Modifying the source in this manner 
does not qualify as being listed a vulnerability.
I disagree on the dupe; see Linux-Security Mailing List,
&quot;[linux-security] Cfinger (Yet more :)&quot; at
http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as
if v1.2.3 is vulnerable, perhaps 1.3.0 also. CVE-1999-0813 pertains
to 1.4.x and below and shows up two years later.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0244" seq="1999-0244">
<status>Entry</status>
<desc>Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</desc>
<refs>
<ref source="NAI">NAI-23</ref>
<ref source="XF">radius-accounting-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0245" seq="1999-0245">
<status>Entry</status>
<desc>Some configurations of NIS+ in Linux allowed attackers to log in as the user &quot;+&quot;.</desc>
<refs>
<ref source="BUGTRAQ">19950907 Linux NIS security problem hole and fix</ref>
<ref source="XF">linux-plus</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0246" seq="1999-0246">
<status>Candidate</status>
<phase date="19990630">Proposed</phase>
<desc>HP Remote Watch allows a remote user to gain root access.</desc>
<refs>
<ref source="XF">hp-remote</ref>
</refs>
<votes>
<accept count="4">Frech, Hill, Northcutt, Prosser</accept>
<noop count="1">Baker</noop>
<recast count="1">Christey</recast>
</votes>
<comments>
<comment voter="Frech">Comment: Determine if it's RemoteWatch or Remote Watch.</comment>
<comment voter="Christey">HP:HPSBUX9610-039 alludes to multiple vulnerabilities in
Remote Watch (the advisory uses two words, not one, for the
&quot;Remote Watch&quot; name)

ADDREF BUGTRAQ:19961015 HP/UX Remote Watch (was Re: BoS: SOD remote exploit)
URL:http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=199610151351.JAA18241@grymoire.crd.ge.com</comment>
<comment voter="Prosser">agree that the advisory mentions two vulnerabilities in Remote
Watch, one being a socket connection and other with the showdisk utility
which seems to be a suid vulnerability.  Never get much details on this
anywhere since the recommendation is to remove the program since it is
obsolete and superceded by later tools. Believe the biggest concern here is
to just not run the tool at all.</comment>
<comment voter="Christey">CIAC:H-16
Also, http://www.cert.org/vendor_bulletins/VB-96.20.hp
And possibly AUSCERT:AA-96.07 at
ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.07.HP-UX.Remote.Watch.vul</comment>
<comment voter="Christey">Also BUGTRAQ:19961013 BoS: SOD remote exploit
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419969&amp;w=2
Include &quot;remwatch&quot; in the description to facilitate search.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0247" seq="1999-0247">
<status>Entry</status>
<desc>Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp">19970721 INN news server vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1443">1443</ref>
<ref source="XF">inn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0248" seq="1999-0248">
<status>Entry</status>
<desc>A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.</desc>
<refs>
<ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</ref>
<ref source="CONFIRM" url="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0249" seq="1999-0249">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Windows NT RSHSVC program allows remote users to execute arbitrary commands.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Wall</modify>
<noop count="2">Northcutt, Shostack</noop>
<recast count="1">Christey</recast>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Wall">Windows NT Rshsvc.exe from the Windows NT Resource Kit allows
remote
users to execute arbitrary commands.
Source: rshsvc.txt from the Windows NT Resource Kit.</comment>
<comment voter="Frech">XF:rsh-svc</comment>
<comment voter="Christey">MSKB:Q158320, last reviewed in January 1999, refers to a case
where remote users coming from authorized machines are
allowed access regardless of what .rhosts says.  XF:rsh-svc
refers to a bug circa 1997 where any remote entity could
execute commands as system.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0250" seq="1999-0250">
<status>Candidate</status>
<phase date="20010301">Modified</phase>
<desc>Denial of service in Qmail through long SMTP commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref>
<ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref>
<ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
<ref source="XF">qmail-leng</ref>
</refs>
<votes>
<accept count="2">Hill, Meunier</accept>
<modify count="1">Frech</modify>
<reject count="1">Baker</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:qmail-rcpt</comment>
<comment voter="Christey">DUPE CVE-1999-0418 and CVE-1999-0144?</comment>
<comment voter="Christey">Dan Bernstein, author of Qmail, says that this is not a
vulnerability in qmail because Unix has built-in resource
limits that can restrict the size of a qmail process; other
limits can be specified by the administrator.  See
http://cr.yp.to/qmail/venema.html

Significant discussion of this issue took place on the qmail
list.  The fundamental question appears to be whether 
application software should set its own limits, or rely
on limits set by the parent operating system (in this case,
UNIX).  Also, some people said that the only problem was that
the suggested configuration was not well documented, but this
was refuted by others.

See the following threads at
http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html
&quot;Denial of service (qmail-smtpd)&quot;
&quot;qmail-dos-2.c, another denial of service&quot;
&quot;[PATCH] denial of service&quot;
&quot;just another qmail denial-of-service&quot;
&quot;the UNIX way&quot;
&quot;Time for a reality check&quot;

Also see Bugtraq threads on a different vulnerability that
is related to this topic:
BUGTRAQ:19990903 Web servers / possible DOS Attack / mime header flooding
http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html</comment>
<comment voter="Baker">This appears to be the same vulnerability listed in CAN 1999-0144.  In reading
through both bugtraq postings, the one that is referenced by 0144 is
based on a shell code exploit to cause memory exhaustion. The bugtraq
posting referenced by this entry refers explicitly to the prior
posting for 0144, and states that the same effect could be
accomplished by a perl exploit, which was then attached.</comment>
<comment voter="Baker">http://www.securityfocus.com/archive/1/6969    CVE-1999-0144
http://www.securityfocus.com/archive/1/6970    CVE-1999-0250

Both references should be added to CVE-1999-0144, and CVE-1999-0250
should likely be rejected.</comment>
<comment voter="CHANGE">[Baker changed vote from REVIEWING to REJECT]</comment>
<comment voter="Christey">XF:qmail-leng no longer exists; check with Andre to see if they
regarded it as a duplicate as well.

qmail-dos-1.c, as published by Wietse Venema (CVE-1999-0250)
in &quot;BUGTRAQ:19970612 Denial of service (qmail-smtpd)&quot;, does not
use any RCPT commands.  Instead, it sends long strings
of &quot;X&quot; characters.  A followup by &quot;super@UFO.ORG&quot; includes
an exploit that claims to do the same thing; however, that
exploit does not send long strings of X characters - it sends
a large number of RCPT commands.  It appears that super@ufo.org
followed up to the wrong message.

qmail-dos-2.c, as published by Wietse Venema (CVE-1999-0144)
in &quot;BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack&quot;
sends a large number of RCPT commands.

ADDREF BUGTRAQ:19970612 Denial of service (qmail-smtpd)
ADDREF BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack

Also see a related thread:
BUGTRAQ:19990308 SMTP server account probing
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100018214316&amp;w=2

This also describes a problem with mail servers not being able
to handle too many &quot;RCPT TO&quot; requests.  A followup message
notes that application-level protection is used in Sendmail
to prevent this:
BUGTRAQ:19990309 Re: SMTP server account probing
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92101584629263&amp;w=2
The person further says, &quot;This attack can easily be
prevented with configuration methods.&quot;</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0251" seq="1999-0251">
<status>Entry</status>
<desc>Denial of service in talk program allows remote attackers to disrupt a user's display.</desc>
<refs>
<ref source="XF">talkd-flash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0252" seq="1999-0252">
<status>Entry</status>
<desc>Buffer overflow in listserv allows arbitrary command execution.</desc>
<refs>
<ref source="XF">smtp-listserv</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0253" seq="1999-0253">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.</desc>
<refs>
<ref source="XF">http-iis-2e</ref>
<ref source="L0PHT">19970319</ref>
</refs>
<votes>
<accept count="9">Armstrong, Baker, Bishop, Blake, Cole, Collins, Frech, Landfield, Northcutt</accept>
<modify count="1">LeBlanc</modify>
<noop count="3">Ozancin, Prosser, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">This is a problem that was introduced after patching a
previous dot bug with the iis-fix hotfix (see CVE-1999-0154).
Since the hotfix introduced the problem, this should be
treated as a seaprate issue.</comment>
<comment voter="Wall">Agree with the comment.</comment>
<comment voter="LeBlanc">- this one is so old, I don't remember it at all and can't verify or
deny the issue. If you can find some documentation that says we fixed it (KB
article, hotfix, something), then I would change this to ACCEPT</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="Christey">BID:1814
URL:http://www.securityfocus.com/bid/1814</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0254" seq="1999-0254">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.</desc>
<refs>
<ref source="ISS">Hidden SNMP community in HP OpenView</ref>
<ref source="XF">hpov-hidden-snmp-comm</ref>
</refs>
<votes>
<accept count="2">Baker, Frech</accept>
<noop count="1">Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">What is the proper level of abstraction to use here?  Should
we have a separate entry for each different default community
string?  See:
http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and
http://cve.mitre.org/Board_Sponsors/archives/msg00250.html
http://cve.mitre.org/Board_Sponsors/archives/msg00251.html

Until the associated content decisions have been approved
by the Editorial Board, this candidate cannot be accepted
for inclusion in CVE.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0255" seq="1999-0255">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>Buffer overflow in ircd allows arbitrary command execution.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Hill, Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Prosser</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:irc-bo</comment>
<comment voter="Christey">This is too general and doesn't have any references.  The
XF reference doesn't appear toe xist any more.

Perhaps this reference would help:
BUGTRAQ:19970701 ircd buffer overflow</comment>
<comment voter="Baker">It appears that the XForce entry has been corrected, and there is a patch posted in the original bugtraq post.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0256" seq="1999-0256">
<status>Entry</status>
<desc>Buffer overflow in War FTP allows remote execution of commands.</desc>
<refs>
<ref source="XF">war-ftpd</ref>
<ref source="OSVDB" url="http://www.osvdb.org/875">875</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0257" seq="1999-0257">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Nestea variation of teardrop IP fragmentation denial of service.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:nestea-linux-dos</comment>
<comment voter="Christey">Not sure how many separate &quot;instances&quot; of Teardrop
and its ilk.  Also see comments on CVE-1999-0001.

See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258

Is CVE-1999-0001 the same as CVE-1999-0052?  That one is related
to nestea (CVE-1999-0257) and probably the one described in
BUGTRAQ:19981023 nestea v2 against freebsd 3.0-Release
The patch for nestea is in ip_input.c around line 750.
The patches for CVE-1999-0001 are in lines 388&amp;446.  So, 
CVE-1999-0001 is different from CVE-1999-0257 and CVE-1999-0052.
The FreeBSD patch for CVE-1999-0052 is in line 750.
So, CVE-1999-0257 and CVE-1999-0052 may be the same, though
CVE-1999-0052 should be RECAST since this bug affects Linux
and other OSes besides FreeBSD.

Also see BUGTRAQ:19990909 CISCO and nestea.

Finally, note that there is no fundamental difference between
nestea and nestea2/nestea-v2; they are different ports that
exploit the same problem.

The original nestea advisory is at
http://www.technotronic.com/rhino9/advisories/06.htm
but notice that the suggested fix is in line 375 of
ip_fragment.c, not ip_input.c.</comment>
<comment voter="Christey">See the SCO advisory at:
http://www.securityfocus.com/templates/advisory.html?id=1411
which may further clarify the issue.</comment>
<comment voter="Christey">BUGTRAQ:19980501 nestea does other things
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925819&amp;w=2
BUGTRAQ:19980508 nestea2 and HP Jet Direct cards.
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925870&amp;w=2
BUGTRAQ:19981027 nestea v2 against freebsd 3.0-Release
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90951521507669&amp;w=2

Nestea source code is in
MISC:http://oliver.efri.hr/~crv/security/bugs/Linux/ipfrag6.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0258" seq="1999-0258">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Bonk variation of teardrop IP fragmentation denial of service.</desc>
<refs>
</refs>
<votes>
<modify count="2">Frech, Wall</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Wall">Reference Q179129</comment>
<comment voter="Frech">XF:teardrop-mod</comment>
<comment voter="Christey">Not sure how many separate &quot;instances&quot; of Teardrop there are.
See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258</comment>
<comment voter="Christey">See the SCO advisory at:
http://www.securityfocus.com/templates/advisory.html?id=1411
which may further clarify the issue.</comment>
<comment voter="Christey">BUGTRAQ:19980108 bonk.c
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88429524325956&amp;w=2
NTBUGTRAQ:19980108 bonk.c
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=88433857200304&amp;w=2
NTBUGTRAQ:19980109 Re: Bonk.c
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=88441302913269&amp;w=2
NTBUGTRAQ:19980304 Update on wide-spread NewTear Denial of Service attacks
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=88901842000424&amp;w=2
BUGTRAQ:19980304 Update on wide-spread NewTear Denial of Service attacks
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88903296104349&amp;w=2
CIAC:I-031a
http://ciac.llnl.gov/ciac/bulletins/i-031a.shtml

CERT summary CS-98.02 implies that bonk, boink, and newtear
all exploit the same vulnerability.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0259" seq="1999-0259">
<status>Entry</status>
<desc>cfingerd lists all users on a system via search.**@target.</desc>
<refs>
<ref source="BUGTRAQ">19970523 cfingerd vulnerability</ref>
<ref source="XF">cfinger-user-enumeration</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0260" seq="1999-0260">
<status>Entry</status>
<desc>The jj CGI program allows command execution via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19961224 jj cgi</ref>
<ref source="XF">http-cgi-jj</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0261" seq="1999-0261">
<status>Candidate</status>
<phase date="20000827">Modified</phase>
<desc>Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.</desc>
<refs>
<ref source="BUGTRAQ">19980504 Netmanage Holes</ref>
<ref source="MISC" url="http://www.insecure.org/sploits/netmanage.chameleon.overflows.html">http://www.insecure.org/sploits/netmanage.chameleon.overflows.html</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Landfield</modify>
<noop count="3">Christey, Northcutt, Ozancin</noop>
</votes>
<comments>
<comment voter="Frech">XF:chamelion-smtp-dos</comment>
<comment voter="Landfield">- Specify what &quot;a crash&quot; means.</comment>
<comment voter="Christey">ADDREF XF:chameleon-smtp-dos ?  (but it's not on the web site)</comment>
<comment voter="Christey">Consider adding BID:2387</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0262" seq="1999-0262">
<status>Entry</status>
<desc>Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</desc>
<refs>
<ref source="BUGTRAQ">19980804 remote exploit in faxsurvey cgi-script</ref>
<ref source="BUGTRAQ">19980804 PATCH: faxsurvey</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2056">2056</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1532">http-cgi-faxsurvey(1532)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0263" seq="1999-0263">
<status>Entry</status>
<desc>Solaris SUNWadmap can be exploited to obtain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173">00173</ref>
<ref source="XF">sun-sunwadmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0264" seq="1999-0264">
<status>Entry</status>
<desc>htmlscript CGI program allows remote read access to files.</desc>
<refs>
<ref source="XF">http-htmlscript-file-access</ref>
<ref source="BUGTRAQ">Jan27,1998</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0265" seq="1999-0265">
<status>Entry</status>
<desc>ICMP redirect messages may crash or lock up a host.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154174">Q154174</ref>
<ref source="ISS">ICMP Redirects Against Embedded Controllers</ref>
<ref source="XF">icmp-redirect</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0266" seq="1999-0266">
<status>Entry</status>
<desc>The info2www CGI script allows remote file access or remote command execution.</desc>
<refs>
<ref source="BUGTRAQ">19980303 Vulnerabilites in some versions of info2www CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1995">1995</ref>
<ref source="XF">http-cgi-info2www</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0267" seq="1999-0267">
<status>Entry</status>
<desc>Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</desc>
<refs>
<ref source="XF">http-port</ref>
<ref source="CERT">CA-95.04.NCSA.http.daemon.for.unix.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0268" seq="1999-0268">
<status>Entry</status>
<desc>MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</desc>
<refs>
<ref source="BUGTRAQ">19980630 Security vulnerabilities in MetaInfo products</ref>
<ref source="BUGTRAQ">19980703 Followup to MetaInfo vulnerabilities</ref>
<ref source="OSVDB" url="http://www.osvdb.org/110">110</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3969">3969</ref>
<ref source="XF">metaweb-server-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0269" seq="1999-0269">
<status>Entry</status>
<desc>Netscape Enterprise servers may list files through the PageServices query.</desc>
<refs>
<ref source="XF">netscape-server-pageservices</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0270" seq="1999-0270">
<status>Entry</status>
<desc>Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as &quot;pfdisplay&quot;) for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">19980317 IRIX performer_tools bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P">19980401-01-P</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-041.shtml">I-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/64">64</ref>
<ref source="OSVDB" url="http://www.osvdb.org/134">134</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/810">sgi-pfdispaly(810)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0271" seq="1999-0271">
<status>Candidate</status>
<phase date="19990925">Modified</phase>
<desc>Progressive Networks Real Video server (pnserver) can be crashed remotely.</desc>
<refs>
<ref source="BUGTRAQ">19980115 pnserver exploit..</ref>
<ref source="BUGTRAQ">19980817 Re: Real Audio Server Version 5 bug?</ref>
</refs>
<votes>
<accept count="3">Baker, Blake, Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Prosser</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">Problem confirmed by RealServer vendor (URL listed in Bugtraq
posting), but may be multiple codebases since several
Real Audio servers are affected.

Also, this may be the same as BUGTRAQ:19991105 RealNetworks RealServer G2 buffer overflow.
See CVE-1999-0896</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">ADDREF XF:realvideo-telnet-dos</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0272" seq="1999-0272">
<status>Entry</status>
<desc>Denial of service in Slmail v2.5 through the POP3 port.</desc>
<refs>
<ref source="XF">slmail-username-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0273" seq="1999-0273">
<status>Entry</status>
<desc>Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</desc>
<refs>
<ref source="XF">sun-telnet-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0274" seq="1999-0274">
<status>Entry</status>
<desc>Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</desc>
<refs>
<ref source="NAI">NAI-5</ref>
<ref source="XF">nt-dns-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0275" seq="1999-0275">
<status>Entry</status>
<desc>Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</desc>
<refs>
<ref source="XF">nt-dnscrash</ref>
<ref source="XF">nt-dnsver</ref>
<ref source="MS">Q169461</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0276" seq="1999-0276">
<status>Entry</status>
<desc>mSQL v2.0.1 and below allows remote execution through a buffer overflow.</desc>
<refs>
<ref source="XF">msql-debug-bo</ref>
<ref source="SEKURE">sekure.01-99.msql</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0277" seq="1999-0277">
<status>Entry</status>
<desc>The WorkMan program can be used to overwrite any file to get root access.</desc>
<refs>
<ref source="XF">workman</ref>
<ref source="CERT">CA-96.23.workman_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0278" seq="1999-0278">
<status>Entry</status>
<desc>In IIS, remote attackers can obtain source code for ASP files by appending &quot;::$DATA&quot; to the URL.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx">MS98-003</ref>
<ref source="XF">iis-asp-data-check</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913">oval:org.mitre.oval:def:913</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0279" seq="1999-0279">
<status>Entry</status>
<desc>Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19971217 CGI security hole in EWS (Excite for Web Servers)</ref>
<ref source="BUGTRAQ">19980115 Excite announcement</ref>
<ref source="CERT">VB-98.01.excite</ref>
<ref source="XF">excite-cgi-search-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0280" seq="1999-0280">
<status>Entry</status>
<desc>Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</desc>
<refs>
<ref source="NTBUGTRAQ">19970317 Internet Explorer Bug #4</ref>
<ref source="CIAC">H-38</ref>
<ref source="XF">http-ie-lnkurl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0281" seq="1999-0281">
<status>Entry</status>
<desc>Denial of service in IIS using long URLs.</desc>
<refs>
<ref source="XF">http-iis-longurl</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0282" seq="1999-0282">
<status>Candidate</status>
<phase date="20050830">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1584, CVE-1999-1586.  Reason: This candidate combined references from one issue with the description from another issue.  Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Dik</accept>
<modify count="1">Frech</modify>
<noop count="1">Ozancin</noop>
<recast count="1">Prosser</recast>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:sun-loadmodule
XF:sun-modload (CERT CA-93.18 very old!)</comment>
<comment voter="Prosser">Believe the reference given, 95-12,  is referencing a later
loadmodule(8) setuid problem in the X11/NeWS windowing system.  There is an
earlier, similar setuid vulnerability in the CA-93.18, CIAC G-02 advisories
for the SunOS 4.1.x/Solbourne and OpenWindow 3.0.  In fact, there may be the
same as the HP patches are 100448-02 for the 93 loadmodule/modload
vulnerability and 100448-03 for the 95 loadmodule vulnerability which
normally indicated a patch update.  Looks like the original patch either
didn't completely fix the problem or it resurfaced in X11 NeWS.  Can't tell
much beyond that and this is my opinion only as have no way to check it.  
Which one is this CVE referencing?  I accept both.</comment>
<comment voter="Dik">There are three similar Sun bug ids associated with the patches.
1076118 loadmodule has a security vulnerability
1148753 loadmodule has a security vulnerability
1222192 loadmodule has a security vulnerability
as well as:
1137491
Ancient stuff.</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="Christey">This is distinct from CVE-1999-1584 - CVE-1999-1584 is for
CA-93.18.</comment>
<comment voter="CHANGE">[Christey changed vote from REVIEWING to REJECT]</comment>
<comment voter="Christey">This candidate combines two separate issues.  It uses the CERT
alert reference from 1995, from one issue, but a description that
is associated with a separate issue.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0283" seq="1999-0283">
<status>Candidate</status>
<phase date="19991203">Modified</phase>
<desc>The Java Web Server would allow remote users to obtain the source code for CGI programs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88256790401004&amp;w=2">19970716 Viewable .jhtml source with JavaWebServer</ref>
</refs>
<votes>
<accept count="7">Baker, Blake, Cole, Collins, Dik, Northcutt, Wall</accept>
<modify count="1">Frech</modify>
<noop count="5">Armstrong, Bishop, Christey, Landfield, Prosser</noop>
<reviewing count="1">Ozancin</reviewing>
</votes>
<comments>
<comment voter="Wall">Acknowledged by vendor at
http://www.sun.com/software/jwebserver/techinfo/jws112info.html.</comment>
<comment voter="Baker">Vulnerability Reference (HTML)	Reference Type
http://www.securityfocus.com/archive/1/7260	Misc Defensive Info
http://www.sun.com/software/jwebserver/techinfo/jws112info.html Vendor Info</comment>
<comment voter="Christey">BID:1891
URL:http://www.securityfocus.com/bid/1891</comment>
<comment voter="Christey">Add version number (1.1 beta) and details of attack (appending
a . or a \)

The Sun URL referenced by Dave Baker no longer exists, so I
wasn't able to verify that it addressed the problem described
in the Bugtraq post.  This might not even be Sun's
&quot;Java Web Server,&quot; as CVE-2001-0186 describes some product
called &quot;Free Java Web Server&quot;</comment>
<comment voter="Dik">There appears to be some confusion.

The particular bug seems to be on in JWS 1.1beta or 1.1 which was fixed
in 1.1.2 (get foo.jthml source by appending &quot;.&quot; of &quot;\&quot; to URL)

There are other bugs that give access and that require a configuration
change.

http://www.sun.com/software/jwebserver/techinfo/security_advisory.html</comment>
<comment voter="Christey">Need to make sure to create CAN's for the other bugs,
as documented in:
NTBUGTRAQ:19980724 Alert: New Source Bug Affect Sun JWS
http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222454131622&amp;w=2
BUGTRAQ:19980725 Alert: New Source Bug Affect Sun JWS
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526086&amp;w=2
The reported bugs are:
1) file read by appending %20
2) Directly call /servlet/file
URL:http://www.sddt.com/cgi-bin/Subscriber?/library/98/07/24/tbd.html
#2 is explicitly mentioned in the Sun advisory for
CVE-1999-0283.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:javawebserver-cgi-source(5383)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0284" seq="1999-0284">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.</desc>
<refs>
<ref source="XF">smtp-helo-bo</ref>
</refs>
<votes>
<accept count="2">Blake, Northcutt</accept>
<modify count="3">Frech, Levy, Ozancin</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">&quot;Windows NT-based mail servers&quot; (A trademark thing, and for clarification)
XF:mdaemon-helo-bo
XF:lotus-notes-helo-crash
XF:slmail-helo-overflow
XF:smtp-helo-bo (mentions several products)
XF:smtp-exchangedos</comment>
<comment voter="Levy">- Need one per software. Each one should be its own
vulnerability.</comment>
<comment voter="Ozancin">=&gt; Windows NT is correct</comment>
<comment voter="Christey">These are probably multiple codebases, so we'll need to use
dot notation.  Also need to see if this should be merged
with CVE-1999-0098 (Sendmail SMTP HELO).</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0285" seq="1999-0285">
<status>Candidate</status>
<phase date="19990630">Proposed</phase>
<desc>Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.</desc>
<refs>
</refs>
<votes>
<accept count="1">Hill</accept>
<noop count="2">Baker, Wall</noop>
<reject count="2">Christey, Frech</reject>
</votes>
<comments>
<comment voter="Christey">No references, no information.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to REJECT]</comment>
<comment voter="Frech">No references; closest documented match is with
CVE-2001-0346, but that's for Windows 2000.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0286" seq="1999-0286">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.</desc>
<refs>
</refs>
<votes>
<accept count="3">Armstrong, Cole, Shostack</accept>
<modify count="3">Blake, Levy, Wall</modify>
<noop count="5">Baker, Bishop, Landfield, Northcutt, Ozancin</noop>
<reject count="1">Frech</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Wall">In some NT web servers, appending a dot at the end of a URL may
allows attackers to read source code for active pages.
Source:  MS Knowledge Base Article Q163485 - &quot;Active Server Pages Script Appears
in Browser&quot;</comment>
<comment voter="Frech">In the meantime, reword description as 'Windows NT' (trademark issue)</comment>
<comment voter="Christey">Q163485 does not refer to a space, it refers to a dot.
However, I don't have other references.

Reading source code with a dot appended is in CVE-1999-0154,
which will be proposed.  A subsequent bug similar to the
dot bug is CVE-1999-0253.</comment>
<comment voter="Levy">NTBUGTRAQ: http://www.securityfocus.com/archive/2/22014
NTBUGTRAQ: http://www.securityfocus.com/archive/2/22019
BID 273</comment>
<comment voter="Blake">Reference:  http://www.allaire.com/handlers/index.cfm?ID=10967</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to REJECT]</comment>
<comment voter="Frech">BID articles)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0287" seq="1999-0287">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Vulnerability in the Wguest CGI program.</desc>
<refs>
</refs>
<votes>
<modify count="2">Frech, Shostack</modify>
<noop count="4">Blake, Levy, Northcutt, Wall</noop>
<reject count="2">Baker, Christey</reject>
</votes>
<comments>
<comment voter="Shostack">allows file reading</comment>
<comment voter="Frech">XF:http-cgi-webcom-guestbook</comment>
<comment voter="Christey">CVE-1999-0287 is probably a duplicate of CVE-1999-0467.  In
NTBUGTRAQ:19990409 Webcom's CGI Guestbook for Win32 web servers
Mnemonix says that he had previously reported on a similar
problem.  Let's refer to the NTBugtraq posting as
CVE-1999-0467.  We will refer to the &quot;previous report&quot; as
CVE-1999-0287, which could be found at:
http://oliver.efri.hr/~crv/security/bugs/NT/httpd41.html

0287 describes an exploit via the &quot;template&quot; hidden variable.
The exploit describes manually editing the HTML form to
change the filename to read from the template variable.

The exploit as described in 0467 encodes the template variable
directly into the URL.  However, hidden variables are also
encoded into the URL, which would have looked the same to
the web server regardless of the exploit.  Therefore 0287
and 0467 are the same.</comment>
<comment voter="Christey">BID:2024</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0288" seq="1999-0288">
<status>Entry</status>
<desc>The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</desc>
<refs>
<ref source="NTBUGTRAQ">19970801 WINS flooding</ref>
<ref source="BUGTRAQ">19970801 WINS flooding</ref>
<ref source="BUGTRAQ">19970815 Re: WINS flooding</ref>
<ref source="MISC" url="http://safenetworks.com/Windows/wins.html">http://safenetworks.com/Windows/wins.html</ref>
<ref source="MSKB">155701</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1233">nt-winsupd-fix(1233)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0289" seq="1999-0289">
<status>Entry</status>
<desc>The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</desc>
<refs>
</refs>
</item>

<item type="CVE" name="CVE-1999-0290" seq="1999-0290">
<status>Entry</status>
<desc>The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</desc>
<refs>
<ref source="BUGTRAQ">19980221 WinGate DoS</ref>
<ref source="BUGTRAQ">19980326 WinGate Intermediary Fix/Update</ref>
<ref source="XF">wingate-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0291" seq="1999-0291">
<status>Entry</status>
<desc>The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</desc>
<refs>
<ref source="XF">wingate-unpassworded</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0292" seq="1999-0292">
<status>Entry</status>
<desc>Denial of service through Winpopup using large user names.</desc>
<refs>
<ref source="XF">nt-winpopup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0293" seq="1999-0293">
<status>Entry</status>
<desc>AAA authentication on Cisco systems allows attackers to execute commands without authorization.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/aaapair-pub.shtml</ref>
<ref source="XF">cisco-ios-aaa-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0294" seq="1999-0294">
<status>Entry</status>
<desc>All records in a WINS database can be deleted through SNMP for a denial of service.</desc>
<refs>
<ref source="XF">nt-wins-snmp2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0295" seq="1999-0295">
<status>Entry</status>
<desc>Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</desc>
<refs>
<ref source="XF">sun-sysdef</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157">00157</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0296" seq="1999-0296">
<status>Entry</status>
<desc>Solaris volrmmount program allows attackers to read any file.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162">00162</ref>
<ref source="XF">sun-volrmmount</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0297" seq="1999-0297">
<status>Entry</status>
<desc>Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</desc>
<refs>
<ref source="NAI">NAI-3</ref>
<ref source="AUSCERT">AA-96.21</ref>
<ref source="CIAC">H-17</ref>
<ref source="XF">vixie-cron</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0298" seq="1999-0298">
<status>Candidate</status>
<phase date="20000524">Modified</phase>
<desc>ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp">19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Levy, Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="3">Baker, Christey, Shostack</noop>
</votes>
<comments>
<comment voter="Christey">ADDREF BID:1441
URL:http://www.securityfocus.com/bid/1441</comment>
<comment voter="Dik">If you run with &quot;-ypset&quot;, then you're always insecure.
With ypsetme, only root on the local host
can run ypset in Solaris 2.x+.
Probably true for SunOS 4, hence my vote.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">ADDREF XF:ypbind-ypset-root</comment>
<comment voter="CHANGE">[Dik changed vote from REVIEWING to ACCEPT]</comment>
<comment voter="Dik">This vulnerability does exist in SunOS 4.x in non default configurations.
In Solaris 2.x, the vulnerability only applies to files named &quot;cache_binding&quot;
and not all files ending in .2
Both releases are not vulnerable in the default configuration (both
disabllow ypset by default which prevents this problem from occurring)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0299" seq="1999-0299">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD lpd through long DNS hostnames.</desc>
<refs>
<ref source="NAI">NAI-9</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6093">6093</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0300" seq="1999-0300">
<status>Entry</status>
<desc>nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155">00155</ref>
<ref source="XF">sun-niscache</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0301" seq="1999-0301">
<status>Entry</status>
<desc>Buffer overflow in SunOS/Solaris ps command.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149">00149</ref>
<ref source="AUSCERT">AUSCERT-97.17</ref>
<ref source="XF">sun-ps2bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0302" seq="1999-0302">
<status>Entry</status>
<desc>SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176">00176</ref>
<ref source="XF">sun-ftp-server</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0303" seq="1999-0303">
<status>Entry</status>
<desc>Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</desc>
<refs>
<ref source="XF">bnu-uucpd-bo</ref>
<ref source="RSI">RSI.0002.05-18-98.BNU.UUCPD</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0304" seq="1999-0304">
<status>Entry</status>
<desc>mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</desc>
<refs>
<ref source="XF">bsd-mmap</ref>
<ref source="FREEBSD">FreeBSD-SA-98:02</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0305" seq="1999-0305">
<status>Entry</status>
<desc>The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</desc>
<refs>
<ref source="OPENBSD">Feb15,1998 &quot;IP Source Routing Problem&quot;</ref>
<ref source="MISC" url="http://www.openbsd.org/advisories/sourceroute.txt">http://www.openbsd.org/advisories/sourceroute.txt</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11502">11502</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/736">bsd-sourceroute(736)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0306" seq="1999-0306">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>buffer overflow in HP xlock program.</desc>
<refs>
<ref source="XF">hp-xlock</ref>
</refs>
<votes>
<accept count="3">Baker, Frech, Northcutt</accept>
<modify count="1">Prosser</modify>
<noop count="1">Shostack</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Prosser">This is another of those with multiple affected OSs.
Refs:  CA-97.13, http://207.237.120.45/linux/xlock-exploit.txt,
HPSBUX9711-073, SGI 19970502-02-PX, Sun Bulletin 000150</comment>
<comment voter="Christey">XF:hp-xlock points to SGI:19970502-02-PX which says this is
the same problem as in CERT:CA-97.13, which is CVE-1999-0038.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0307" seq="1999-0307">
<status>Candidate</status>
<phase date="19991207">Modified</phase>
<desc>Buffer overflow in HP-UX cstm program allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">19961116 This week: turn me on, dead man</ref>
<ref source="XF">hpux-cstm-bo</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<noop count="3">Baker, Prosser, Shostack</noop>
<recast count="1">Christey</recast>
</votes>
<comments>
<comment voter="Prosser">only ref I can find is an old SOD exploit on
www.outpost9.com</comment>
<comment voter="Christey">MERGE CVE-1999-0336 (the exact exploit works with both
cstm and mstm, which are clearly part of the same package,
so CD:SF-EXEC says to merge them.)

Also, there does not seem to be any recognition of this problem
by HP.  The only other information besides the Bugtraq post
is the SOD exploit.

See the original post:
http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1996-11-15&amp;msg=Pine.LNX.3.91.961116112242.15276J-100000@underground.org</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0308" seq="1999-0308">
<status>Entry</status>
<desc>HP-UX gwind program allows users to modify arbitrary files.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</ref>
<ref source="XF">hpux-gwind-overwrite</ref>
<ref source="CIAC">H-03: HP-UX suid Vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0309" seq="1999-0309">
<status>Entry</status>
<desc>HP-UX vgdisplay program gives root access to local users.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056">HPSBUX9702-056</ref>
<ref source="XF">hpux-vgdisplay</ref>
<ref source="CIAC">H-27: HP-UX vgdisplay Buffer Overrun Vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0310" seq="1999-0310">
<status>Entry</status>
<desc>SSH 1.2.25 on HP-UX allows access to new user accounts.</desc>
<refs>
<ref source="XF">ssh-1225</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0311" seq="1999-0311">
<status>Entry</status>
<desc>fpkg2swpk in HP-UX allows local users to gain root access.</desc>
<refs>
<ref source="XF">hpux-fpkg2swpk</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0312" seq="1999-0312">
<status>Entry</status>
<desc>HP ypbind allows attackers with root privileges to modify NIS data.</desc>
<refs>
<ref source="XF">nis-ypbind</ref>
<ref source="CERT">CA-93:01.REVISED.HP.NIS.ypbind.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0313" seq="1999-0313">
<status>Entry</status>
<desc>disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/214">214</ref>
<ref source="OSVDB" url="http://www.osvdb.org/936">936</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1441">sgi-disk-bandwidth(1441)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0314" seq="1999-0314">
<status>Entry</status>
<desc>ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/213">213</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6788">6788</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1199">sgi-ioconfig(1199)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0315" seq="1999-0315">
<status>Entry</status>
<desc>Buffer overflow in Solaris fdformat command gives root access to local users.</desc>
<refs>
<ref source="XF">fdformat-bo</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138">00138</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0316" seq="1999-0316">
<status>Entry</status>
<desc>Buffer overflow in Linux splitvt command gives root access to local users.</desc>
<refs>
<ref source="XF">linux-splitvt</ref>
<ref source="CIAC">G-08</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0317" seq="1999-0317">
<status>Candidate</status>
<phase date="19991216">Modified</phase>
<desc>Buffer overflow in Linux su command gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">19990818 slackware-3.5 /bin/su buffer overflow</ref>
<ref source="XF">su-bo</ref>
</refs>
<votes>
<accept count="3">Frech, Hill, Northcutt</accept>
<noop count="1">Prosser</noop>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">DUPE CVE-1999-0845?
Also, ADDREF XF:unixware-su-username-bo
A report summary by Aleph One states that nobody was able to
confirm this problem on any Linux distribution.</comment>
<comment voter="Baker">If this is the same as the unixware, the n it is a dupe of 1999-0845.  There is about a two and half month difference in the bugtraq reporting of these.
Sounds like the same bug however...</comment>
<comment voter="Christey">XF:su-bo no longer seems to exist.
How about XF:linux-subo(734) ?
http://xforce.iss.net/static/734.php

BID:475 also seems to describe the same problem
(http://www.securityfocus.com/bid/475) in which case,
vsyslog is blamed in:
BUGTRAQ:19971220 Linux vsyslog() overflow
http://www.securityfocus.com/archive/1/8274</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0318" seq="1999-0318">
<status>Entry</status>
<desc>Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19961125 Security Problems in XMCD</ref>
<ref source="BUGTRAQ">19961125 XMCD v2.1 released (was: Security Problems in XMCD)</ref>
<ref source="XF">xmcd-envbo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0319" seq="1999-0319">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.</desc>
<refs>
<ref source="XF">xmcd-tiflestr</ref>
</refs>
<votes>
<accept count="3">Frech, Hill, Northcutt</accept>
<noop count="2">Baker, Prosser</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">BUGTRAQ:19961126 Security Problems in XMCD 2.1
A followup to this post says that xmcd is not suid here.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0320" seq="1999-0320">
<status>Entry</status>
<desc>SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/166">00166</ref>
<ref source="XF">sun-rpc.cmsd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0321" seq="1999-0321">
<status>Entry</status>
<desc>Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</desc>
<refs>
<ref source="XF">sun-kcms-configure-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0322" seq="1999-0322">
<status>Entry</status>
<desc>The open() function in FreeBSD allows local attackers to write to arbitrary files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-97:05</ref>
<ref source="XF">freebsd-open</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6092">6092</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0323" seq="1999-0323">
<status>Entry</status>
<desc>FreeBSD mmap function allows users to modify append-only or immutable files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:04</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc">1998-003</ref>
<ref source="XF">bsd-mmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0324" seq="1999-0324">
<status>Entry</status>
<desc>ppl program in HP-UX allows local users to create root files through symlinks.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</ref>
<ref source="CIAC">H-31</ref>
<ref source="XF">hp-ppllog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0325" seq="1999-0325">
<status>Entry</status>
<desc>vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</desc>
<refs>
<ref source="XF">hp-vhe</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0326" seq="1999-0326">
<status>Entry</status>
<desc>Vulnerability in HP-UX mediainit program.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071">HPSBUX9710-071</ref>
<ref source="XF">hp-mediainit</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0327" seq="1999-0327">
<status>Entry</status>
<desc>SGI syserr program allows local users to corrupt files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
<ref source="XF">sgi-syserr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0328" seq="1999-0328">
<status>Entry</status>
<desc>SGI permissions program allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
<ref source="XF">sgi-permtool</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0329" seq="1999-0329">
<status>Entry</status>
<desc>SGI mediad program allows local users to gain root access.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX">19980602-01-PX</ref>
<ref source="XF">sgi-mediad</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0330" seq="1999-0330">
<status>Candidate</status>
<phase date="20000105">Modified</phase>
<desc>Linux bdash game has a buffer overflow that allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ">19940101 (No Subject)</ref>
<ref source="XF">bdash-bo</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="3">Northcutt, Shostack, Wall</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:bdash-bo</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0331" seq="1999-0331">
<status>Candidate</status>
<phase date="20040811">Modified</phase>
<desc>Buffer overflow in Internet Explorer 4.0(1).</desc>
<refs>
<ref source="XF">msie-bo</ref>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<modify count="2">Frech, Shostack</modify>
<recast count="1">Prosser</recast>
<reject count="2">Christey, LeBlanc</reject>
</votes>
<comments>
<comment voter="Shostack">this is a high cardinality item</comment>
<comment voter="Prosser">needs to be more specific.</comment>
<comment voter="Frech">Replace reference with XF:iemk-bug (msie-bo is obsolete and a vague
duplicate)
Description (from xfdb): Some versions of Internet Explorer for Windows
contain a vulnerability that may crash the broswer when a malicious web site
contains a certain kind of URL (that begins with &quot;mk://&quot;) with more
characters than the browser supports. </comment>
<comment voter="Christey">The description is too vague.</comment>
<comment voter="LeBlanc">too vague</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0332" seq="1999-0332">
<status>Entry</status>
<desc>Buffer overflow in NetMeeting allows denial of service and remote command execution.</desc>
<refs>
<ref source="XF">nt-netmeeting</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q184346">Q184346</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0333" seq="1999-0333">
<status>Candidate</status>
<phase date="19990925">Modified</phase>
<desc>HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.</desc>
<refs>
<ref source="RSI">RSI.0009.09-08-98.HP-UX.OMNIBACK</ref>
<ref source="HP">HPSBUX9810-085</ref>
<ref source="XF">omniback-remote</ref>
</refs>
<votes>
<accept count="2">Baker, Frech</accept>
<modify count="1">Prosser</modify>
<recast count="1">Christey</recast>
</votes>
<comments>
<comment voter="Prosser">additional source
HP Security Bulletin 85
http://us-support.external.hp.com
http://europe-support.external.hp.com</comment>
<comment voter="Christey">Two separate bugs, so SF-LOC says this candidate should be
split</comment>
<comment voter="Christey">ADDREF CIAC:J-007
URL:http://ciac.llnl.gov/ciac/bulletins/j-007.shtml</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0334" seq="1999-0334">
<status>Entry</status>
<desc>In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</desc>
<refs>
<ref source="XF">sol-startup</ref>
<ref source="CERT">CA-93.19.Solaris.Startup.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0335" seq="1999-0335">
<status>Entry</status>
<desc>DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</desc>
<refs>
</refs>
</item>

<item type="CAN" name="CVE-1999-0336" seq="1999-0336">
<status>Candidate</status>
<phase date="19991207">Modified</phase>
<desc>Buffer overflow in mstm in HP-UX allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ">19961116 This week: turn me on, dead man</ref>
<ref source="XF">hpux-mstm-bo</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<noop count="3">Baker, Prosser, Shostack</noop>
<recast count="1">Christey</recast>
</votes>
<comments>
<comment voter="Prosser">same as CVE-1999-0307, only ref I can find is an old SOD
exploit on www.outpost9.com</comment>
<comment voter="Christey">MERGE CVE-1999-0307 (the exact exploit works with both
cstm and mstm, which are clearly part of the same package,
so CD:SF-EXEC says to merge them.)

Also, there does not seem to be any recognition of this problem
by HP.  The only other information besides the Bugtraq post
is the SOD exploit.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0337" seq="1999-0337">
<status>Entry</status>
<desc>AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</desc>
<refs>
<ref source="CERT">CA-94.10.IBM.AIX.bsh.vulnerability.html</ref>
<ref source="XF">ibm-bsh</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0338" seq="1999-0338">
<status>Entry</status>
<desc>AIX Licensed Program Product performance tools allow local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-perf-tools</ref>
<ref source="CERT">CA-94.03.AIX.performance.tools </ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0339" seq="1999-0339">
<status>Entry</status>
<desc>Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</desc>
<refs>
<ref source="XF">sol-sun-libauth</ref>
<ref source="RSI">RSI.0007.05-26-98</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0340" seq="1999-0340">
<status>Entry</status>
<desc>Buffer overflow in Linux Slackware crond program allows local users to gain root access.</desc>
<refs>
<ref source="KSRT">005</ref>
<ref source="XF">linux-crond</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0341" seq="1999-0341">
<status>Entry</status>
<desc>Buffer overflow in the Linux mail program &quot;deliver&quot; allows local users to gain root access.</desc>
<refs>
<ref source="KSRT">006</ref>
<ref source="XF">linux-deliver</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0342" seq="1999-0342">
<status>Entry</status>
<desc>Linux PAM modules allow local users to gain root access using temporary files.</desc>
<refs>
<ref source="REDHAT">http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam</ref>
<ref source="XF">linux-pam-passwd-tmprace</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0343" seq="1999-0343">
<status>Entry</status>
<desc>A malicious Palace server can force a client to execute arbitrary programs.</desc>
<refs>
<ref source="BUGTRAQ">19981002 Announcements from The Palace (fwd)</ref>
<ref source="XF">palace-malicious-servers-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0344" seq="1999-0344">
<status>Entry</status>
<desc>NT users can gain debug-level access on a system process using the Sechole exploit.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx">MS98-009</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q190288">Q190288</ref>
<ref source="XF">nt-priv-fix</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0345" seq="1999-0345">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.</desc>
<refs>
</refs>
<votes>
<accept count="2">Blake, Cole</accept>
<modify count="2">Frech, Wall</modify>
<noop count="4">Bishop, Landfield, Northcutt, Ozancin</noop>
<recast count="1">Meunier</recast>
<reject count="4">Armstrong, Baker, LeBlanc, Levy</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Wall">Invalid ICMP datagram fragments causes a denial of service in Windows 95 and
Windows NT systems.
Reference: Q154174.
Jolt is also known as sPING, ICMP bug, Icenewk, and Ping of Death.
It is a modified teardrop 2 attack.  </comment>
<comment voter="Frech">XF:nt-ssping
ADDREF XF:ping-death
ADDREF XF:teardrop-mod
ADDREF XF:mpeix-echo-request-dos</comment>
<comment voter="Christey">I can't tell whether the Jolt exploit at:

http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1997-06-28&amp;msg=Pine.BSF.3.95q.970629163422.3264A-200000@apollo.tomco.net

is exploiting any different flaw than teardrop does.</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="Baker">Jolt (original) is basically just a fragmented oversized ICMP that
kills Win boxes ala Ping of Death.
Teardrop is altering the offset in fragmented tcp packets so that the
end of subsequent fragments is inside first packet...
Teardrop 2 is UDP packets, if I remember right.
Seems like Jolt (original, not jolt 2) is just exploit code that
creates a ping of death (CVE 1999-0128)</comment>
<comment voter="Levy">I tend to agree with Baker.</comment>
<comment voter="CHANGE">[Armstrong changed vote from REVIEWING to REJECT]</comment>
<comment voter="Armstrong">This code does not use fragment overlap.  It is simply a large ICMP echo request.</comment>
<comment voter="Christey">See the SCO advisory at:
http://www.securityfocus.com/templates/advisory.html?id=1411
which may further clarify the issue.</comment>
<comment voter="LeBlanc">This is a hodge-podge of DoS attacks. Jolt isn't the same
thing as ping of death - POD was an oversized ICMP packet, Jolt froze
Linux and Solaris (and I think not NT), IIRC Jolt2 did get NT boxes.
Teardrop and teardrop2 were related attacks (usually ICMP frag attacks),
but each of these is a distinct vulnerability, affected a discrete group
of systems, and should have distinct CVE numbers. CVE entries should be
precise as to what the problem is.</comment>
<comment voter="Meunier">I agree with Leblanc in that Jolt is multi-faceted.  Jolt has
characteristics of Ping of Death AND teardrop, but it doesn't do
either exactly.  Moreover, it sends a truncated IP fragment.  I
disagree with Armstrong; jolt uses overlapping fragments.  It's not a
simple ping of death either.  It may be that the author's intent was
to construct a &quot;super attack&quot; somehow combining elements of other
vulnerabilities to try to make it more potent.  In any case it
succeeded in confusing the CVE board :-).

I notice that Jolt uses echo replies (type 0) instead of echo
requests (to get past firewalls?).  Jolt is peculiar in that it also
sends numerous overlapping fragments.  The &quot;Pascal Simulator&quot; :-) says
it sends:

- 172 fragments of length 400 with offset starting at 5120 and</comment>
<comment voter="increasing by about 47 (odd arithmetic of 5120 OR ((n* 380) ">&gt; 3)),
which eventually results in sending fragments inside an already</comment>
<comment voter="covered area once ((n* 380) ">&gt; 3) is greater than 5120, which occurs
when n is reaches 108.  This would look a bit like TearDrop if
fragments were reassembled on-the-fly.

- 1 fragment such that the total length of all the fragments
is greater than 65535 (my calculation is 172*380 + 418 = 65778; the
comment about 65538 must be wrong).  The last packet is size 418
according to the IP header but the buffer is of size 400.  The sendto
takes as argument the size of the buffer so a truncated packet is
sent.

So, I am not sure if the problem is because the last packet
doesn't extend to the payload it says it has or because the total size
of all fragments is greater than 65535.  The author says it may take
more than one sending, so perhaps this has to do with an incorrect
error handling and recovery.  One would need to experiment and isolate
each of those characteristics and test them independently.  Inasmuch
as each of those things is likely a different vulnerability, then I
agree with Leblanc that this entry should be split.  I'll try that if
I ever get bored.  Jolt 2 should also have a different entry (see
below).

Jolt 2 runs in an infinite loop, sending the same fragmented
IP packet, which can pretend to be &quot;ICMP&quot; or &quot;UDP&quot; data; however this
is meaningless, as it's just a late fragment of an IP packet.  The
attack works only as long as packets are sent.  According to
http://www.securityfocus.com/archive/1/62170 the packets are
truncated, and would overflow over the 65535 byte limit, which is
similar to Jolt.  Note that Jolt does send that much data whereas
jolt2 doesn't.  Since jolt2 is simpler and narrower than jolt, and it
has weaker consequences, I believe that it's a different
vulnerability.

&quot;Jolt 2 vulnerability causes a temporary denial-of-service in
Windows-type OSes&quot; would be a title for it.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0346" seq="1999-0346">
<status>Entry</status>
<desc>CGI PHP mlog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="XF">http-cgi-php-mlog</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3397">3397</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0347" seq="1999-0347">
<status>Candidate</status>
<phase date="20051028">Modified</phase>
<desc>Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a &quot;%01&quot; character in an &quot;about:&quot; Javascript URL, which causes Internet Explorer to use the domain specified after the character.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91745430007021&amp;w=2">19990126 Javascript ecurity bug in Internet Explorer</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91756771207719&amp;w=2">19990126 Javascript ecurity bug in Internet Explorer</ref>
</refs>
<votes>
<accept count="4">Baker, LeBlanc, Levy, Northcutt</accept>
<modify count="2">Frech, Prosser</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Prosser">this is a modified Cross-Frame vulnerability that circumvents
the original Cross-Frame Patch.  Addressed in MS Bulletin MS99.012
http://www.microsoft.com/security/bulletins/ms99-012.asp</comment>
<comment voter="Christey">Duplicate of CVE-1999-0490?</comment>
<comment voter="LeBlanc">If Prosser is correct that this is MS99-012, accept</comment>
<comment voter="Christey">BUGTRAQ:19990126 Javascript ecurity bug in Internet Explorer
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91745430007021&amp;w=2
NTBUGTRAQ:19990128 Javascript %01 bug in Internet Explorer
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91756771207719&amp;w=2
BID:197
URL:http://www.securityfocus.com/bid/197</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:ie-window-spoof(2069)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0348" seq="1999-0348">
<status>Entry</status>
<desc>IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</desc>
<refs>
<ref source="NTBUGTRAQ">Jan27,1999</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q197003">Q197003</ref>
<ref source="OSVDB" url="http://www.osvdb.org/930">930</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0349" seq="1999-0349">
<status>Entry</status>
<desc>A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/IIS Remote FTP Exploit/DoS Attack.html">IIS Remote FTP Exploit/DoS Attack</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx">MS99-003</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q188348">Q188348</ref>
<ref source="BUGTRAQ">Jan27,1999</ref>
<ref source="XF">iis-remote-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0350" seq="1999-0350">
<status>Entry</status>
<desc>Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</desc>
<refs>
<ref source="L0PHT">Feb8,1999</ref>
<ref source="XF">clearcase-temp-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0351" seq="1999-0351">
<status>Entry</status>
<desc>FTP PASV &quot;Pizza Thief&quot; denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</desc>
<refs>
<ref source="INFOWAR">01</ref>
<ref source="MISC" url="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt">http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3389">pasv-pizza-thief-dos(3389)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0352" seq="1999-0352">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.</desc>
<refs>
<ref source="ISS">Multiple vulnerabilities in ControlIT(tm) (formerly Remotely Possible/32) enterprise management software</ref>
<ref source="XF">controlit-passwd-encrypt</ref>
</refs>
<votes>
<accept count="2">Baker, Frech</accept>
<noop count="2">Northcutt, Wall</noop>
<recast count="1">Ozancin</recast>
</votes>
<comments>
<comment voter="Ozancin">Can we combine this with CVE-1999-0356 - ControlIT(tm) 4.5 and earlier uses
weak encryption.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0353" seq="1999-0353">
<status>Entry</status>
<desc>rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091">HPSBUX9902-091</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-026.shtml">J-026</ref>
<ref source="XF">pcnfsd-world-write</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0354" seq="1999-0354">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content.  Also applies to Outlook when the client views a malicious email message.</desc>
<refs>
<ref source="NTBUGTRAQ">Jan27,1999</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-002.asp">MS99-002</ref>
</refs>
<votes>
<accept count="3">Baker, Ozancin, Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:word97-template-macro</comment>
<comment voter="Christey">CHANGEREF NTBUGTRAQ:19990127 IE 4/5/Outlook + Word 97 security hole
URL:http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91747570922757&amp;w=2
BID:196
http://www.securityfocus.com/bid/196</comment>
<comment voter="Christey">MSKB:Q214652
http://support.microsoft.com/support/kb/articles/q214/6/52.asp</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0355" seq="1999-0355">
<status>Entry</status>
<desc>Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</desc>
<refs>
<ref source="ISS">Multiple vulnerabilities in ControlIT(tm) (formerly Remotely Possible/32) enterprise management software</ref>
<ref source="XF">controlit-reboot</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0356" seq="1999-0356">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.</desc>
<refs>
<ref source="ISS">Multiple vulnerabilities in ControlIT(tm) (formerly Remotely Possible/32) enterprise management software</ref>
<ref source="XF">controlit-bookfile-access</ref>
</refs>
<votes>
<accept count="2">Baker, Frech</accept>
<noop count="2">Northcutt, Wall</noop>
<recast count="1">Ozancin</recast>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-0357" seq="1999-0357">
<status>Entry</status>
<desc>Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted &quot;oshare&quot; packets, possibly involving invalid fragmentation offsets.</desc>
<refs>
<ref source="BUGTRAQ">19990125 Win98 crash?</ref>
<ref source="XF">win98-oshare-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0358" seq="1999-0358">
<status>Entry</status>
<desc>Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
<ref source="COMPAQ">SSRT0583U</ref>
<ref source="XF">du-inc</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-027.shtml">J-027</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0359" seq="1999-0359">
<status>Candidate</status>
<phase date="20010214">Proposed</phase>
<desc>ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.</desc>
<refs>
<ref source="BUGTRAQ">19990127 UNIX shell modem access vulnerabilities</ref>
<ref source="XF">ptylogin-dos</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<modify count="1">Baker</modify>
</votes>
<comments>
<comment voter="Frech">XF:ptylogin-dos </comment>
<comment voter="Baker">Should say &quot;... lock out a modem, ...&quot; rather than &quot;... locking out modems...&quot;</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0360" seq="1999-0360">
<status>Candidate</status>
<phase date="20000530">Modified</phase>
<desc>MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91763097004101&amp;w=2">19990130 Security Advisory for Internet Information Server 4 with Site</ref>
<ref source="NTBUGTRAQ">Jan29,1999</ref>
</refs>
<votes>
<accept count="6">Blake, Cole, Collins, Landfield, Northcutt, Wall</accept>
<modify count="3">Baker, Frech, LeBlanc</modify>
<noop count="4">Armstrong, Christey, Ozancin, Prosser</noop>
</votes>
<comments>
<comment voter="Christey">I can't find the original Bugtraq posting (it appears that
mnemonix discovered the problem).</comment>
<comment voter="LeBlanc">- if there was a fix or a KB article, I'd ACCEPT. A vuln based on a
BUGTRAQ posting we can't find could be anything. </comment>
<comment voter="Baker">Vulnerability Reference (HTML)	Reference Type
http://www.securityfocus.com/archive/1/12218	Misc Defensive InfoVulnerability Reference (HTML)	Reference Type
THis is the URL for the Bugtraq posting.  It was cross posted to
NT Bugtraq as well, but identical text.  It was Mnemonix...</comment>
<comment voter="Christey">BID:1811
URL:http://www.securityfocus.com/bid/1811</comment>
<comment voter="Christey">CHANGEREF BUGTRAQ add &quot;Server 2.&quot; to the subject.
Also standardize NTBUGTRAQ reference title.</comment>
<comment voter="Christey">Add &quot;uploadn.asp&quot; to the description.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:siteserver-user-dir-permissions(5384)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0361" seq="1999-0361">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.</desc>
<refs>
<ref source="BUGTRAQ">Jan29,1999</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="2">Northcutt, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:compulink-pw-laserfiche(1679)
Normalize BUGTRAQ reference to:
BUGTRAQ:19990129 Compulink LaserFiche Client/Server - unencrypted passwords</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0362" seq="1999-0362">
<status>Entry</status>
<desc>WS_FTP server remote denial of service through cwd command.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02021999.html">AD02021999</ref>
<ref source="XF">wsftp-remote-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/217">217</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0363" seq="1999-0363">
<status>Entry</status>
<desc>SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</desc>
<refs>
<ref source="BUGTRAQ">Feb02,1999</ref>
<ref source="XF">plp-lpc-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/328">328</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0364" seq="1999-0364">
<status>Candidate</status>
<phase date="20000426">Modified</phase>
<desc>Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91816470220259&amp;w=2">19990204 Microsoft Access 97 Stores Database Password as Plaintext</ref>
</refs>
<votes>
<accept count="2">Baker, LeBlanc</accept>
<modify count="1">Frech</modify>
<noop count="2">Northcutt, Wall</noop>
</votes>
<comments>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:access-weak-passwords(1774)
An older published reference (from our own Adam) would be
better:
ailab.coderpunks Newsgroup, 1998/06/23 &quot;Re: MS Access 2.0&quot;
http://x15.dejanews.com/[ST_rn=ps]/getdoc.xp?AN=365308578&amp;CONTEXT=9192
07028.1462108427&amp;hitnum=1</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0365" seq="1999-0365">
<status>Entry</status>
<desc>The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</desc>
<refs>
<ref source="BUGTRAQ">Feb04,1999</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0366" seq="1999-0366">
<status>Entry</status>
<desc>In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx">MS99-004</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q214840">Q214840</ref>
<ref source="XF">nt-sp4-auth-error</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0367" seq="1999-0367">
<status>Entry</status>
<desc>NetBSD netstat command allows local users to access kernel memory.</desc>
<refs>
<ref source="NETBSD">1999-002</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7571">7571</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0368" seq="1999-0368">
<status>Entry</status>
<desc>Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</desc>
<refs>
<ref source="NETECT">palmetto.ftpd</ref>
<ref source="CERT">CA-99.03</ref>
<ref source="XF">palmetto-ftpd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0369" seq="1999-0369">
<status>Entry</status>
<desc>The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183">00183</ref>
<ref source="XF">sun-sdtcm-convert-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0370" seq="1999-0370">
<status>Candidate</status>
<phase date="19991210">Modified</phase>
<desc>In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.</desc>
<refs>
<ref source="SUN">00184</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/165">165</ref>
</refs>
<votes>
<accept count="4">Baker, Dik, Northcutt, Prosser</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Reference: XF:sun-man</comment>
<comment voter="Christey">ADDREF CIAC:J-028

Is the Linux man symlink problem the same as the one for Sun?
See BUGTRAQ:19990602 /tmp symlink problems in SuSE Linux 6.1
Also see BID:305</comment>
<comment voter="Dik">sun bug 4154565</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0371" seq="1999-0371">
<status>Entry</status>
<desc>Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</desc>
<refs>
<ref source="BUGTRAQ">19990211 Lynx /tmp problem</ref>
<ref source="CERT">VB-97.05.lynx</ref>
<ref source="XF">lynx-temp-files-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0372" seq="1999-0372">
<status>Entry</status>
<desc>The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx">MS99-005</ref>
<ref source="XF">nt-backoffice-setup</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q217004">Q217004</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0373" seq="1999-0373">
<status>Entry</status>
<desc>Buffer overflow in the &quot;Super&quot; utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</desc>
<refs>
<ref source="ISS">Buffer Overflow in &quot;Super&quot; package in Debian Linux</ref>
<ref source="XF">linux-super-bo</ref>
<ref source="XF">linux-super-logging-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0374" seq="1999-0374">
<status>Entry</status>
<desc>Debian GNU/Linux cfengine package is susceptible to a symlink attack.</desc>
<refs>
<ref source="DEBIAN">19990215</ref>
<ref source="BUGTRAQ">Feb16,1999</ref>
<ref source="XF">linux-cfengine-symlinks</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0375" seq="1999-0375">
<status>Entry</status>
<desc>Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</desc>
<refs>
<ref source="NAI">February 16, 1999</ref>
<ref source="BUGTRAQ">Feb16,1999</ref>
<ref source="XF">nfr-webd-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0376" seq="1999-0376">
<status>Entry</status>
<desc>Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx">MS99-006</ref>
<ref source="BUGTRAQ">Feb20,1999</ref>
<ref source="L0PHT">Feb18,1999</ref>
<ref source="XF">nt-knowndlls-list</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0377" seq="1999-0377">
<status>Entry</status>
<desc>Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.</desc>
<refs>
<ref source="BUGTRAQ">Feb22,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0378" seq="1999-0378">
<status>Entry</status>
<desc>InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.</desc>
<refs>
<ref source="BUGTRAQ">19990222 BlackHats Advisory -- InterScan VirusWall</ref>
<ref source="BUGTRAQ">19990225 Patch for InterScan VirusWall for Unix now available</ref>
<ref source="XF">viruswall-http-request</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6167">6167</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0379" seq="1999-0379">
<status>Entry</status>
<desc>Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx">MS99-007</ref>
<ref source="BUGTRAQ">19990223 Microsoft Security Bulletin (MS99-007)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/498">498</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1019">1019</ref>
<ref source="XF">win-resourcekit-taskpads</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0380" seq="1999-0380">
<status>Entry</status>
<desc>SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91999015212415&amp;w=2">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91996412724720&amp;w=2">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92110501504997&amp;w=2">SLmail 3.2 Build 3113 (Web Administration Security Fix)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/497">497</ref>
<ref source="XF" url="http://xforce.iss.net/static/5392.php">slmail-ras-ntfs-bypass(5392)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0381" seq="1999-0381">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.990225011801.12757A-100000@eleet">19990225 SUPER buffer overflow</ref>
<ref source="XF">linux-super-logging-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/342">342</ref>
</refs>
<votes>
<accept count="7">Baker, Blake, Cole, Frech, Landfield, Levy, Ozancin</accept>
<modify count="1">Bishop</modify>
<noop count="2">Armstrong, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">Is this the same as CVE-1999-0373?  They both have the same
X-Force reference.

BID:342 suggests that there are two.

http://www.debian.org/security/1999/19990215a suggests
that there are two.  However, CVE-1999-0373 is written up in
a fashion that is too general; and both XF:linux-super-bo and
XF:linux-super-logging-bo refer to CVE-1999-0373.
CVE-1999-0373 may need to be split.
</comment>
<comment voter="Frech">From what I can surmise, ISS released the original advisory (attached to
linux-super-bo), and Sekure SDI expanded on it by releasing another related
overflow in syslog (which is linux-super-logging-bo).

When I was originally assigning these issues, I placed both XF references
and the ISS advisory on the -0373 candidate, since there was nothing else
available. Based on the information above, I'd request that
XF:linux-super-logging-bo be removed from CVE-1999-0373.</comment>
<comment voter="Christey">Given Andre's feedback, these are different issues.
CVE-1999-0373 does not need to be split because the ISS
reference is sufficient to distinguish that CVE from this
candidate; however, the CVE-1999-0373 description should
probably be modified slightly.</comment>
<comment voter="Bishop">(as indicated by Christey)</comment>
<comment voter="CHANGE">[Cole changed vote from NOOP to ACCEPT]</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="Christey">There are 2 bugs, as confirmed by the super author at:
BUGTRAQ:19990226 Buffer Overflow in Super (new)
http://www.securityfocus.com/archive/1/12713
BID:397 also seems to cover this one, and it may cover
CVE-1999-0373 as well.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0382" seq="1999-0382">
<status>Entry</status>
<desc>The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx">MS99-008</ref>
<ref source="XF">nt-screen-saver</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0383" seq="1999-0383">
<status>Entry</status>
<desc>ACC Tigris allows public access without a login.</desc>
<refs>
<ref source="BUGTRAQ">19990103 Tigris vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/183">183</ref>
<ref source="OSVDB" url="http://www.osvdb.org/267">267</ref>
<ref source="XF">acc-tigris-login</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0384" seq="1999-0384">
<status>Entry</status>
<desc>The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.</desc>
<refs>
<ref source="XF">forms-vuln-patch</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx">MS99-001</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0385" seq="1999-0385">
<status>Entry</status>
<desc>The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx">MS99-009</ref>
<ref source="ISS">LDAP Buffer overflow against Microsoft Directory Services</ref>
<ref source="XF">ldap-exchange-overflow</ref>
<ref source="XF">ldap-mds-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0386" seq="1999-0386">
<status>Entry</status>
<desc>Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx">MS99-010</ref>
<ref source="XF">pws-file-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/111">111</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0387" seq="1999-0387">
<status>Entry</status>
<desc>A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-052.asp">MS99-052</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q168115">Q168115</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/829">829</ref>
<ref source="XF">9x-plaintext-pwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0388" seq="1999-0388">
<status>Entry</status>
<desc>DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</desc>
<refs>
<ref source="XF">datalynx-suguard-relative-paths</ref>
<ref source="L0PHT">Jan3,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3186">3186</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0389" seq="1999-0389">
<status>Candidate</status>
<phase date="19991207">Modified</phase>
<desc>Buffer overflow in the bootp server in the Debian Linux netstd package.</desc>
<refs>
<ref source="DEBIAN">19990104</ref>
<ref source="BUGTRAQ">19990103 [SECURITY] New versions of netstd fixes buffer overflows</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/324">324</ref>
</refs>
<votes>
<accept count="3">Baker, Ozancin, Stracener</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">Is CVE-1999-0389 a duplicate of CVE-1999-0798?  CVE-1999-0389
has January 1999 dates associated with it, while CVE-1999-0798
was reported in late December.

Also, is this the same line of code as CVE-1999-0914?  Both are in
the netstd package, it could look like a library problem.

However, deep in the changelog in the
netstd_3.07-7slink.3.diff on Debian, Herbert Xu includes
the following entry:

+netstd (3.07-7slink.1) frozen; urgency=high
+
+  * bootpd:     Applied patch from Redhat as well as a fix for the overflow in
+                report() (fixes #30675).
+  * netkit-ftp: Applied patch from RedHat that fixes some obscure overflow
+                bugs.
+
+ -- Herbert Xu &lt;herbert@debian.org&gt;  Sat, 19 Dec 1998 14:36:48 +1100

This tells me that two separate bugs are involved.

Note that Red Hat posted *some* fix for *some* bootp problem
in June 1998.  See:
http://www.redhat.com/support/errata/rh42-errata-general.html#bootp</comment>
<comment voter="Frech">XF:debian-netstd-bo</comment>
<comment voter="Christey">Further analysis indicates that this is a duplicate of CVE-1999-0799</comment>
<comment voter="CHANGE">[Christey changed vote from REJECT to REVIEWING]</comment>
<comment voter="Christey">The fix information for BID:324 suggests that there are two
overflows, one of which is in handle_request (bootpd.c) and is
likely related to a file name; but there is another issue in
report (report.c) which also looks like a straightforward
overflow, which would suggest that this is not a duplicate of
CVE-1999-0798 or CVE-1999-0799.

Note: see comments for CVE-1999-0798 which explain how that
candidate is not related to CVE-1999-0799.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0390" seq="1999-0390">
<status>Entry</status>
<desc>Buffer overflow in Dosemu Slang library in Linux.</desc>
<refs>
<ref source="BUGTRAQ">19990104 Dosemu/S-Lang Overflow + sploit</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt">CSSA-1999-006.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/187">187</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0391" seq="1999-0391">
<status>Entry</status>
<desc>The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</desc>
<refs>
<ref source="L0PHT">Jan. 5, 1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0392" seq="1999-0392">
<status>Entry</status>
<desc>Buffer overflow in Thomas Boutell's cgic library version up to 1.05.</desc>
<refs>
<ref source="BUGTRAQ">Jan10,1999</ref>
<ref source="XF">http-cgic-library-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0393" seq="1999-0393">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</desc>
<refs>
<ref source="BUGTRAQ">19981212 ** Sendmail 8.9.2 DoS - exploit ** get what you want!</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91694391227372&amp;w=2">19990121 Sendmail 8.8.x/8.9.x bugware</ref>
<ref source="XF">sendmail-parsing-redirection</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0394" seq="1999-0394">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.</desc>
<refs>
<ref source="BUGTRAQ">19990115 DPEC Online Courseware</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<noop count="1">Christey</noop>
<reject count="1">Frech</reject>
</votes>
<comments>
<comment voter="Frech">If I understand the issue, this HIGHCARD involves insecure web programming. 
If I don't understand, mark this as my first NOOP.</comment>
<comment voter="Christey">CONFIRM:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19990803132618.16407.qmail%40securityfocus.com
ADDREF BID:565
URL:http://www.securityfocus.com/vdb/bottom.html?vid=565</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0395" seq="1999-0395">
<status>Entry</status>
<desc>A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise17.php">19990118 Vulnerability in the BackWeb Polite Agent Protocol</ref>
<ref source="XF">backweb-polite-agent-protocol</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0396" seq="1999-0396">
<status>Entry</status>
<desc>A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="NETBSD">1999-001</ref>
<ref source="OPENBSD">Feb17,1999</ref>
<ref source="XF">netbsd-tcp-race</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0397" seq="1999-0397">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.</desc>
<refs>
<ref source="L0PHT">Jan21,1999</ref>
<ref source="BUGTRAQ">Jan21,1999</ref>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Wall</reject>
</votes>
<comments>
<comment voter="Wall">Reject based on beta copy.</comment>
<comment voter="Frech">XF:quakenbush-pw-appraiser(1652)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0398" seq="1999-0398">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.</desc>
<refs>
<ref source="BUGTRAQ">19990123 SSH 1.x and 2.x Daemon</ref>
<ref source="BUGTRAQ">19990124 SSH Daemon</ref>
<ref source="XF">ssh-exp-account-access</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">Followups to the bugtraq message (1/24/99) indicate that 1.2.27 was not yet
released. v1.2.26 should be substituted in the description for '27.
XF:ssh-exp-account-access</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0399" seq="1999-0399">
<status>Candidate</status>
<phase date="20000105">Modified</phase>
<desc>The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19990124 Mirc 5.5 'DCC Server' hole</ref>
<ref source="XF">mirc-dcc-metachar-filename</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:mirc-dcc-metachar-filename</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0400" seq="1999-0400">
<status>Candidate</status>
<phase date="20000105">Modified</phase>
<desc>Denial of service in Linux 2.2.0 running the ldd command on a core file.</desc>
<refs>
<ref source="BUGTRAQ">19990127 2.2.0 SECURITY (fwd)</ref>
<ref source="XF">linux-kernel-ldd-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/344">344</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">BUGTRAQ:Jan27,1999
(http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-01-22&amp;
msg=Pine.LNX.4.05.9901270538380.539-100000@vitelus.com)
XF:linux-kernel-ldd-dos</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0401" seq="1999-0401">
<status>Candidate</status>
<phase date="20000105">Modified</phase>
<desc>A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.</desc>
<refs>
<ref source="BUGTRAQ">19990202 [patch] /proc race fixes for 2.2.1 (fwd)</ref>
<ref source="XF">linux-race-condition-proc</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:linux-race-condition-proc</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0402" seq="1999-0402">
<status>Entry</status>
<desc>wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</desc>
<refs>
<ref source="BUGTRAQ">Feb2,1999</ref>
<ref source="XF">wget-permissions</ref>
<ref source="DEBIAN">19990220</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0403" seq="1999-0403">
<status>Entry</status>
<desc>A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91821080015725&amp;w=2">19990204 Cyrix bug: freeze in hell, badboy</ref>
<ref source="XF">cyrix-hang</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0404" seq="1999-0404">
<status>Entry</status>
<desc>Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</desc>
<refs>
<ref source="BUGTRAQ">Feb14,1999</ref>
<ref source="XF">mailmax-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0405" seq="1999-0405">
<status>Entry</status>
<desc>A buffer overflow in lsof allows local users to obtain root privilege.</desc>
<refs>
<ref source="HERT">002</ref>
<ref source="BUGTRAQ">Feb18,1999</ref>
<ref source="DEBIAN">19990220a</ref>
<ref source="XF">lsof-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3163">3163</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0406" seq="1999-0406">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.</desc>
<refs>
<ref source="BUGTRAQ">Feb19,1999</ref>
<ref source="XF">digital-networker-bo</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">In description, change 'which' to 'that'.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0407" seq="1999-0407">
<status>Entry</status>
<desc>By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91983486431506&amp;w=2">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92000623021036&amp;w=2">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</ref>
<ref source="XF">iis-iisadmpwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0408" seq="1999-0408">
<status>Entry</status>
<desc>Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</desc>
<refs>
<ref source="BUGTRAQ">19990225 Cobalt root exploit</ref>
<ref source="XF">cobalt-raq-history-exposure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/337">337</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0409" seq="1999-0409">
<status>Entry</status>
<desc>Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</desc>
<refs>
<ref source="BUGTRAQ">19990304 Linux /usr/bin/gnuplot overflow</ref>
<ref source="XF">gnuplot-home-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/319">319</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0410" seq="1999-0410">
<status>Entry</status>
<desc>The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</desc>
<refs>
<ref source="BUGTRAQ">Mar5,1999</ref>
<ref source="XF">sol-cancel</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/293">293</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0411" seq="1999-0411">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access.</desc>
<refs>
<ref source="BUGTRAQ">Feb19,1999</ref>
<ref source="XF">sco-startup-scripts</ref>
</refs>
<votes>
<modify count="2">Baker, Frech</modify>
<noop count="2">Christey, Wall</noop>
</votes>
<comments>
<comment voter="Frech">Neither XFDB nor the BugTraq article (incidentally, shows up as 7 March, not
19 February) does not mention gaining root access... it says a local user
could
&quot;delete or overwrite arbitrary files on the system.&quot;</comment>
<comment voter="Baker">By overwriting arbitrary files, one could then gain root access.  I agree with a minor description change to reflect this.</comment>
<comment voter="Christey">Normalize Bugtraq reference to:
BUGTRAQ:19990307 Little exploit for startup scripts (SCO 5.0.4p).
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92087765014242&amp;w=2
Also, SCO:SB-99.17
ftp://ftp.sco.com/SSE/security_bulletins/SB-99.17c</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0412" seq="1999-0412">
<status>Entry</status>
<desc>In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</desc>
<refs>
<ref source="BUGTRAQ">Feb19,1999</ref>
<ref source="XF">iis-isapi-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/501">501</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0413" seq="1999-0413">
<status>Entry</status>
<desc>A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX">19990301-01-PX</ref>
<ref source="XF">irix-font-path-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0414" seq="1999-0414">
<status>Entry</status>
<desc>In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</desc>
<refs>
<ref source="NAI">Linux Blind TCP Spoofing</ref>
<ref source="XF">linux-blind-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0415" seq="1999-0415">
<status>Entry</status>
<desc>The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.</desc>
<refs>
<ref source="ISS">19990311 Remote Reconfiguration and Denial of Service Vulnerabilities in Cisco 700 ISDN Routers</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
<ref source="XF">cisco-router-commands</ref>
<ref source="XF">cisco-web-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0416" seq="1999-0416">
<status>Entry</status>
<desc>Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.</desc>
<refs>
<ref source="ISS">19990311 Remote Reconfiguration and Denial of Service Vulnerabilities in Cisco 700 ISDN Routers</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
<ref source="XF">cisco-web-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0417" seq="1999-0417">
<status>Entry</status>
<desc>64 bit Solaris 7 procfs allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">Mar9,1999</ref>
<ref source="XF">solaris-psinfo-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/448">448</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1001">1001</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0418" seq="1999-0418">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many &quot;RCPT TO&quot; commands in the same connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100018214316&amp;w=2">19990308 SMTP server account probing</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="3">Baker, Foat, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">DUPE CVE-1999-0144 and CVE-1999-0250?</comment>
<comment voter="Frech">XF:smtp-rctpto-dos(7499)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0419" seq="1999-0419">
<status>Candidate</status>
<phase date="20000105">Modified</phase>
<desc>When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19990319 Microsoft's SMTP service broken/stupid</ref>
<ref source="XF">smtp-4xx-error-dos</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, LeBlanc</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:smtp-4xx-error-dos</comment>
<comment voter="LeBlanc">- if we can find a KB or something that shows that this wasn't just
user error, I'd vote ACCEPT.</comment>
<comment voter="Christey">David Lemson, Microsoft SMTP Service Program Manager,
posted a followup that said &quot;We have confirmed this as a
problem...&quot;
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92171608127206&amp;w=2</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0420" seq="1999-0420">
<status>Entry</status>
<desc>umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</desc>
<refs>
<ref source="NETBSD">1999-006</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0421" seq="1999-0421">
<status>Entry</status>
<desc>During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</desc>
<refs>
<ref source="ISS">Short-Term High-Risk Vulnerability During Slackware 3.6 Network Installations</ref>
<ref source="XF">linux-slackware-install</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/338">338</ref>
<ref source="OSVDB" url="http://www.osvdb.org/981">981</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0422" seq="1999-0422">
<status>Entry</status>
<desc>In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the &quot;noexec&quot; flag set.</desc>
<refs>
<ref source="NETBSD">1999-007</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0423" seq="1999-0423">
<status>Entry</status>
<desc>Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</ref>
<ref source="XF">hp-hpterm-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0424" seq="1999-0424">
<status>Entry</status>
<desc>talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</desc>
<refs>
<ref source="SUSE">Mar18,1999</ref>
<ref source="XF">netscape-talkback-overwrite</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0425" seq="1999-0425">
<status>Entry</status>
<desc>talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</desc>
<refs>
<ref source="SUSE">Mar18,1999</ref>
<ref source="XF">netscape-talkback-kill</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0426" seq="1999-0426">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.</desc>
<refs>
<ref source="BUGTRAQ">19990319 The default permissions on /dev/kmem is insecure.</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:linux-dev-kmem-spoof</comment>
<comment voter="Christey">DUPE CVE-1999-0414
XF:linux-dev-kmem-spoof does not exist.</comment>
<comment voter="Christey">*Now* XF:linux-dev-kmem-spoof(3500) exists...</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0427" seq="1999-0427">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.</desc>
<refs>
<ref source="BUGTRAQ">19990320 Eudora Attachment Buffer Overflow</ref>
<ref source="XF">eudora-long-attachments</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">Change version number to 4.2beta. Second to last paragraph in bugtraq
reference states: &quot;Both the Win 95 and Win NT versions, along with the 4.2
beta of Eudora are affected.&quot;</comment>
<comment voter="Christey">This issue seems to have been rediscovered in
BUGTRAQ:20000515 Eudora Pro &amp; Outlook Overflow - too long filenames again
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95842482413076&amp;w=2

Also see
BUGTRAQ:19990320 Eudora Attachment Buffer Overflow
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92195396912110&amp;w=2

Is this a duplicate/subsumed by CVE-1999-0004?</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0428" seq="1999-0428">
<status>Entry</status>
<desc>OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</desc>
<refs>
<ref source="BUGTRAQ">19990322 OpenSSL/SSLeay Security Alert</ref>
<ref source="XF">ssl-session-reuse</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3936">3936</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0429" seq="1999-0429">
<status>Entry</status>
<desc>The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the &quot;Encrypt Saved Mail&quot; preference.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92221437025743&amp;w=2">19990323</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92241547418689&amp;w=2">19990324 Re: LNotes encryption</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92246997917866&amp;w=2">19990326 Lotus Notes Encryption Bug</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92249282302994&amp;w=2">19990326 Re: Lotus Notes security advisory</ref>
<ref source="XF">lotus-client-encryption</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0430" seq="1999-0430">
<status>Entry</status>
<desc>Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</desc>
<refs>
<ref source="ISS">Remote Denial of Service Vulnerability in Cisco Catalyst Series Ethernet Switches</ref>
<ref source="CISCO">Cisco Catalyst Supervisor Remote Reload</ref>
<ref source="XF">cisco-catalyst-crash</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1103">1103</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0431" seq="1999-0431">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19990324 DoS for Linux 2.1.89 - 2.2.3: 0 length fragment bug</ref>
<ref source="XF">linux-zerolength-fragment  </ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:linux-zerolength-fragment  </comment>
<comment voter="Christey">Consider adding BID:2247</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0432" seq="1999-0432">
<status>Entry</status>
<desc>ftp on HP-UX 11.00 allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094">HPSBUX9903-094</ref>
<ref source="XF">hp-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0433" seq="1999-0433">
<status>Entry</status>
<desc>XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</desc>
<refs>
<ref source="SUSE">Mar28,1999</ref>
<ref source="BUGTRAQ">19990321 X11R6 NetBSD Security Problem</ref>
<ref source="XF">xfree86-temp-directories</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0434" seq="1999-0434">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19990331 Bug in xfs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/359">359</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:xfree86-xfs-symlink-dos</comment>
<comment voter="Christey">Is this the same problem as CVE-1999-0433?  CVE-1999-0433
deals with a symlink attack on one file (/tmp/.X11-unix),
while xfs (this candidate) deals with /tmp/.font-unix
XF:xfree86-xfs-symlink-dos doesn't exist.</comment>
<comment voter="Christey">ADDREF DEBIAN:19990331 symbolic link can be used to make any file world readable
Note: Debian's advisory says that this is not a problem for Debian.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0435" seq="1999-0435">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.</desc>
<refs>
<ref source="HP">HPSBUX9903-096</ref>
</refs>
<votes>
<accept count="2">Baker, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:hp-servicegaurd</comment>
<comment voter="Christey">ADDREF CIAC:J-039</comment>
<comment voter="Christey">Note the typo in Andre's suggested reference.
Normalize to XF:hp-serviceguard(2046)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0436" seq="1999-0436">
<status>Entry</status>
<desc>Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095">HPSBUX9903-095</ref>
<ref source="XF">hp-desms-servers</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0437" seq="1999-0437">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</desc>
<refs>
<ref source="ISS">WebRamp Denial of Service Attacks</ref>
<ref source="XF">webramp-device-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0438" seq="1999-0438">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</desc>
<refs>
<ref source="ISS">WebRamp Denial of Service Attacks</ref>
<ref source="XF">webramp-ipchange</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0439" seq="1999-0439">
<status>Entry</status>
<desc>Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</desc>
<refs>
<ref source="BUGTRAQ">19990405 Re: [SECURITY] new version of procmail with security fixes</ref>
<ref source="DEBIAN">19990422</ref>
<ref source="CALDERA">CSSA-1999:007</ref>
<ref source="XF">procmail-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0440" seq="1999-0440">
<status>Entry</status>
<desc>The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92333596624452&amp;w=2">19990405 Security Hole in Java 2 (and JDK 1.1.x)</ref>
<ref source="CONFIRM" url="http://java.sun.com/pr/1999/03/pr990329-01.html">http://java.sun.com/pr/1999/03/pr990329-01.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1939">1939</ref>
<ref source="XF">java-unverified-code</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0441" seq="1999-0441">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02221999.html">AD02221999</ref>
<ref source="XF">wingate-redirector-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/509">509</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0442" seq="1999-0442">
<status>Entry</status>
<desc>Solaris ff.core allows local users to modify files.</desc>
<refs>
<ref source="BUGTRAQ">19990107 really silly ff.core exploit for Solaris</ref>
<ref source="BUGTRAQ">19990108 ff.core exploit on Solaris (2.)7</ref>
<ref source="BUGTRAQ">19990408 Solaris7 and ff.core</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/327">327</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0443" seq="1999-0443">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
<ref source="XF">bmc-patrol-replay</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">Change &quot;Patrol management software&quot; to &quot;The PATROL management product from
BMC Software&quot;.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0444" seq="1999-0444">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.</desc>
<refs>
<ref source="BUGTRAQ">19990412 ARP problem in Windows9X/NT</ref>
<ref source="XF">windows-arp-dos</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">ADDREF: XF:windows-arp-dos  </comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0445" seq="1999-0445">
<status>Entry</status>
<desc>In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</desc>
<refs>
<ref source="CISCO">Cisco IOS(R) Software Input Access List Leakage with NAT</ref>
<ref source="XF">cisco-natacl-leakage</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1104">1104</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0446" seq="1999-0446">
<status>Entry</status>
<desc>Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</desc>
<refs>
<ref source="NETBSD">1999-008</ref>
<ref source="XF">netbsd-vfslocking-panic</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7051">7051</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0447" seq="1999-0447">
<status>Entry</status>
<desc>Local users can gain privileges using the debug utility in the MPE/iX operating system.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006">HPSBMP9904-006</ref>
<ref source="XF">mpeix-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0448" seq="1999-0448">
<status>Entry</status>
<desc>IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</desc>
<refs>
<ref source="BUGTRAQ">19990121 IIS 4 Request Logging Security Advisory</ref>
<ref source="XF">iis-http-request-logging</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0449" seq="1999-0449">
<status>Entry</status>
<desc>The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</desc>
<refs>
<ref source="BUGTRAQ">19990126 IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="NTBUGTRAQ">19990126 IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="BUGTRAQ">19990125 Re: [NTSEC] IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/193">193</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2">2</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3">3</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4">4</ref>
<ref source="XF">iis-exair-dos</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0450" seq="1999-0450">
<status>Candidate</status>
<phase date="20090622">Modified</phase>
<desc>In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).</desc>
<refs>
<ref source="BUGTRAQ">19990122 Perl.exe and IIS security advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/194">194</ref>
</refs>
<votes>
<accept count="2">Ozancin, Wall</accept>
<noop count="2">Baker, Christey</noop>
<reject count="2">Frech, LeBlanc</reject>
</votes>
<comments>
<comment voter="Frech">Can't find in database.</comment>
<comment voter="Christey">This looks like another discovery of CVE-2000-0071 </comment>
<comment voter="LeBlanc">- I just tried to repro this based on the BUGTRAQ vuln information,
and it does not repro - 
GET /bogus.pl HTTP/1.0
HTTP/1.1 404 Object Not Found
Server: Microsoft-IIS/5.0
Date: Thu, 05 Oct 2000 21:04:20 GMT
Content-Length: 3243
Content-Type: text/html
No path is returned whatsoever. This may have been a problem on some version
of IIS in the past, but the BUGTRAQ ID says all versions are vulnerable.
Let's try and figure out what version had the problem, whether it is
intrinsic to IIS or the result of adding a 3rd party implementation of perl,
and when it got fixed, then we can try again.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to REJECT]</comment>
<comment voter="Christey">Add &quot;no-such-file.pl&quot; as an example to the desc, to facilitate
search (it's used by CGI scanners and in the original example)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0451" seq="1999-0451">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.</desc>
<refs>
<ref source="BUGTRAQ">Jan19,1999</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/343">343</ref>
</refs>
<votes>
<accept count="2">Baker, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:linux-ports-dos(8364)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0452" seq="1999-0452">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A service or application has a backdoor password that was placed there by the developer.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Frech</reject>
</votes>
<comments>
<comment voter="Frech">Much too broad. Also may be HIGHCARD (or will be in the future).</comment>
<comment voter="Baker">I think we want to address this using the dot notation idea.  We do need to address this, just not a separate entry for every single occurance.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0453" seq="1999-0453">
<status>Candidate</status>
<phase date="20040512">Modified</phase>
<desc>An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).</desc>
<refs>
<ref source="BUGTRAQ">19990118 Remote Cisco Identification</ref>
</refs>
<votes>
<accept count="2">Baker, Balinsky</accept>
<modify count="1">Frech</modify>
<noop count="2">Northcutt, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:cisco-ident(2289)
ADDREF BUGTRAQ:19990118 Remote Cisco Identification
In description, probably better to use &quot;Cisco&quot; as product/company name.</comment>
<comment voter="Balinsky">CiscoSecure IDS has a signature for this...ID 3602 Cisco IOS Identity.</comment>
<comment voter="Christey">There may be a slight abstraction problem here, e.g. look
at the candidate for queso/nmap; also see followup Bugtraq post
from &quot;Basement Research&quot; on 19990120 which says that there are
many other features in Cisco products that allow remote
identification.</comment>
<comment voter="Christey">fix typo: &quot;Dicsovery&quot;</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0454" seq="1999-0454">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Christey, Wall</noop>
<reject count="2">Baker, Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">Nmap and queso are the tip of the iceberg and not the most advanced
ways to accomplish this.  To pursue making the world signature free
is as much a vulnerability as having signatures, nay more.</comment>
<comment voter="Frech">XF:decod-nmap(2053)
XF:decod-queso(2048)</comment>
<comment voter="Christey">Add &quot;fingerprinting&quot; to facilitate search.
Some references:
MISC:http://www.insecure.org/nmap/nmap-fingerprinting-article.html
BUGTRAQ:19981228 A few more fingerprinting techniques - time and netmask
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91489155019895&amp;w=2
BUGTRAQ:19990222 Preventing remote OS detection
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91971553006937&amp;w=2
BUGTRAQ:20000901 ICMP Usage In Scanning v2.0 - Research Paper
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96791499611849&amp;w=2
BUGTRAQ:20000912 Using the Unused (Identifying OpenBSD,
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96879267724690&amp;w=2
BUGTRAQ:20000912 The DF Bit Playground (Identifying Sun Solaris &amp; OpenBSD OSs)
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96879481129637&amp;w=2
BUGTRAQ:20000816 TOSing OSs out of the window / Fingerprinting Windows 2000 with
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96644121403569&amp;w=2
BUGTRAQ:20000609 p0f - passive os fingerprinting tool
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96062535628242&amp;w=2</comment>
<comment voter="Baker">I think we can probably reject this as the corollary is that you can identify OS from a IP/TCP packet sent by a system, looking at various parts of the SYN packet.  Unless we believe that all systems should always use identical packet header/identical responses, in which case the protocol should not permit variation.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0455" seq="1999-0455">
<status>Candidate</status>
<phase date="19991210">Modified</phase>
<desc>The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.</desc>
<refs>
<ref source="ALLAIRE">ASB-001</ref>
<ref source="XF">coldfusion-expression-evaluator</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/115">115</ref>
</refs>
<votes>
<accept count="3">Balinsky, Frech, Ozancin</accept>
<modify count="1">Wall</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Wall">The reference should be ASB99-01 (Expression Evaluator Security Issues)
make application plural since there are three sample applications
(openfile.cfm, displayopenedfile.cfm, and exprcalc.cfm).</comment>
<comment voter="Christey">The CD:SF-EXEC and CD:SF-LOC content decisions apply here.
Since there are 3 separate &quot;executables&quot; with the same
(or similar) problem, we need to make sure that CD:SF-EXEC
determines what to do here.  There is evidence that some
of these .cfm scripts have an &quot;include&quot; file, and if so, 
then CD:SF-LOC says that we shouldn't make separate entries
for each of these scripts.  On the other hand, the initial
L0pht discovery didn't include all 3 of these scripts, and
as far as I can tell, Allaire had patched the first problem
before the others were discovered.  So, CD:DISCOVERY-DATE
may argue that we should split these because the problems
were discovered and patched at different times.

In any case, this candidate can not be accepted until the
Editorial Board has accepted the CD:SF-EXEC, CD:SF-LOC,
and CD:DISCOVERY-DATE content decisions.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0457" seq="1999-0457">
<status>Entry</status>
<desc>Linux ftpwatch program allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">Jan17,1999</ref>
<ref source="DEBIAN">19990117</ref>
<ref source="XF">ftpwatch-vuln</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/317">317</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0458" seq="1999-0458">
<status>Entry</status>
<desc>L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.</desc>
<refs>
<ref source="BUGTRAQ">Jan6,1999</ref>
<ref source="XF">l0phtcrack-temp-files</ref>
<ref source="OSVDB" url="http://www.osvdb.org/915">915</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0459" seq="1999-0459">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.</desc>
<refs>
<ref source="XF">linux-milo-halt</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Baker, Northcutt</noop>
<reject count="1">Wall</reject>
</votes>
<comments>
<comment voter="Wall">Reject based on beta copy.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0460" seq="1999-0460">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19990218 Linux autofs overflow in 2.0.36+</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/312">312</ref>
</refs>
<votes>
<accept count="2">Baker, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:linux-autofs-bo(8365)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0461" seq="1999-0461">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">ADDREF XF:pmap-sset</comment>
<comment voter="Christey">CVE-1999-0195 = CVE-1999-0461 ?
If this is approved over CVE-1999-0195, make sure it gets
XF:pmap-sset</comment>
<comment voter="Baker">THis does appear to be a duplicate.  We should accept 1999-0195, since it already has the votes and get rid of this one</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0462" seq="1999-0462">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.</desc>
<refs>
<ref source="BUGTRAQ">19990114 Secuity hole with perl (suidperl) and nosuid mounts on Linux</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/339">339</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:perl-suidperl-bo</comment>
<comment voter="Christey">XF:perl-suidperl-bo doesn't exist.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0463" seq="1999-0463">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service using IRIX fcagent.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX">19981201-01-PX</ref>
<ref source="XF">sgi-fcagent-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0464" seq="1999-0464">
<status>Entry</status>
<desc>Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91553066310826&amp;w=2">19990104 Tripwire mess..</ref>
<ref source="CONFIRM" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6609">6609</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0465" seq="1999-0465">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.</desc>
<refs>
<ref source="XF">http-img-overflow</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<noop count="1">Baker</noop>
<reject count="2">LeBlanc, Wall</reject>
</votes>
<comments>
<comment voter="Wall">Reject based on client-side DoS</comment>
<comment voter="LeBlanc">Client side DOS</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0466" seq="1999-0466">
<status>Entry</status>
<desc>The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</desc>
<refs>
<ref source="NETBSD">1999-009</ref>
<ref source="OSVDB" url="http://www.osvdb.org/905">905</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0467" seq="1999-0467">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the &quot;template&quot; parameter.</desc>
<refs>
<ref source="NTBUGTRAQ">19990409 Webcom's CGI Guestbook for Win32 web servers</ref>
<ref source="XF">http-cgi-webcom-guestbook</ref>
</refs>
<votes>
<accept count="4">Blake, Frech, Landfield, Ozancin</accept>
<noop count="3">Baker, Christey, Northcutt</noop>
</votes>
<comments>
<comment voter="Christey">CVE-1999-0287 is probably a duplicate of CVE-1999-0467.  In
NTBUGTRAQ:19990409 Webcom's CGI Guestbook for Win32 web servers
Mnemonix says that he had previously reported on a similar
problem.  Let's refer to the NTBugtraq posting as
CVE-1999-0467.  We will refer to the &quot;previous report&quot; as
CVE-1999-0287, which can be found at:
http://oliver.efri.hr/~crv/security/bugs/NT/httpd41.html

0287 describes an exploit via the &quot;template&quot; hidden variable.
The exploit describes manually editing the HTML form to
change the filename to read from the template variable.

The exploit as described in 0467 encodes the template variable
directly into the URL.  However, hidden variables are also
encoded into the URL, which would have looked the same to
the web server regardless of the exploit.  Therefore 0287
and 0467 are the same.</comment>
<comment voter="Christey"> 
The CD:SF-EXEC content decision also applies here.  We have 2
programs, wguest.exe and rguest.exe, which appear to have the
same problem.  CD:SF-EXEC needs to be accepted by the Editorial
Board before this candidate can be converted into a CVE
entry.  When finalized, CD:SF-EXEC will decide whether
this candidate should be split or not.</comment>
<comment voter="Christey">BID:2024</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0468" seq="1999-0468">
<status>Entry</status>
<desc>Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref>
<ref source="XF">ie-scriplet-fileread</ref>
<ref source="BUGTRAQ">Apr9,1999</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0469" seq="1999-0469">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.</desc>
<refs>
<ref source="BUGTRAQ">19990409 IE 5.0 security vulnerabilities - %01 bug again</ref>
<ref source="XF">ie-window-spoof</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="2">Baker, Northcutt</noop>
<reject count="3">Christey, Frech, LeBlanc</reject>
</votes>
<comments>
<comment voter="Wall">Reference: Microsoft Security Bulletin MS99-012</comment>
<comment voter="Christey">DUPE CVE-1999-0488</comment>
<comment voter="Frech">Defer to Christey's vote.
However, XF:ie-mshtml-crossframe(2216) assigned to CVE-1999-0488.</comment>
<comment voter="LeBlanc">Duplicate</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0470" seq="1999-0470">
<status>Entry</status>
<desc>A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.</desc>
<refs>
<ref source="BUGTRAQ">19990409 New Novell Remote.NLM Password Decryption Algorithm with Exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/482">482</ref>
<ref source="XF">netware-remotenlm-passwords</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0471" seq="1999-0471">
<status>Entry</status>
<desc>The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the &quot;cancel&quot; button.</desc>
<refs>
<ref source="XF">winroute-config</ref>
<ref source="BUGTRAQ">Apr9,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0472" seq="1999-0472">
<status>Entry</status>
<desc>The SNMP default community name &quot;public&quot; is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.</desc>
<refs>
<ref source="XF">netcache-snmp</ref>
<ref source="BUGTRAQ">Apr7,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0473" seq="1999-0473">
<status>Entry</status>
<desc>The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.</desc>
<refs>
<ref source="BUGTRAQ">19990407 rsync 2.3.1 release - security fix</ref>
<ref source="CALDERA">CSSA-1999:010.0</ref>
<ref source="DEBIAN">19990823</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/145">145</ref>
<ref source="XF">rsync-permissions</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0474" seq="1999-0474">
<status>Entry</status>
<desc>The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.</desc>
<refs>
<ref source="XF">icq-webserver-read</ref>
<ref source="BUGTRAQ">Apr5,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0475" seq="1999-0475">
<status>Entry</status>
<desc>A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.</desc>
<refs>
<ref source="XF">procmail-race</ref>
<ref source="BUGTRAQ">Apr5,1999</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0476" seq="1999-0476">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.</desc>
<refs>
<ref source="BUGTRAQ">19990331 Potential vulnerability in SCO TermVision Windows 95 client</ref>
<ref source="XF">sco-termvision-password</ref>
</refs>
<votes>
<accept count="3">Baker, Frech, Ozancin</accept>
<noop count="3">LeBlanc, Northcutt, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0477" seq="1999-0477">
<status>Candidate</status>
<phase date="19991210">Modified</phase>
<desc>The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.</desc>
<refs>
<ref source="L0PHT">Cold Fusion App Server</ref>
<ref source="XF">coldfusion-expression-evaluator</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/115">115</ref>
</refs>
<votes>
<accept count="4">Baker, Christey, Frech, Ozancin</accept>
<reject count="1">Wall</reject>
</votes>
<comments>
<comment voter="Wall">Duplicate of 0455</comment>
<comment voter="Christey">CVE-1999-0477 and CVE-1999-0455 were discovered at different
times.  Also, the attack was different.  So &quot;Same Attack&quot; and
&quot;Same Time of Discovery&quot; dictate that these should remain
separate.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0478" seq="1999-0478">
<status>Entry</status>
<desc>Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097">HPSBUX9904-097</ref>
<ref source="XF">sendmail-headers-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0479" seq="1999-0479">
<status>Entry</status>
<desc>Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092">HPSBUX9903-092</ref>
<ref source="XF">netscape-server-dos</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0480" seq="1999-0480">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19980315 Midnight Commander /tmp race</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:midnight-commander-symlink-dos</comment>
<comment voter="Christey">XF:midnight-commander-symlink-dos(3505)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0481" seq="1999-0481">
<status>Entry</status>
<desc>Denial of service in &quot;poll&quot; in OpenBSD.</desc>
<refs>
<ref source="OPENBSD">Mar22,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7556">7556</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0482" seq="1999-0482">
<status>Entry</status>
<desc>OpenBSD kernel crash through TSS handling, as caused by the crashme program.</desc>
<refs>
<ref source="OPENBSD">Mar21,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7557">7557</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0483" seq="1999-0483">
<status>Entry</status>
<desc>OpenBSD crash using nlink value in FFS and EXT2FS filesystems.</desc>
<refs>
<ref source="OPENBSD">Feb25,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6129">6129</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0484" seq="1999-0484">
<status>Entry</status>
<desc>Buffer overflow in OpenBSD ping.</desc>
<refs>
<ref source="OPENBSD">Feb23,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6130">6130</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0485" seq="1999-0485">
<status>Entry</status>
<desc>Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.</desc>
<refs>
<ref source="OPENBSD">Feb19,1999</ref>
<ref source="XF">openbsd-ipintr-race</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7558">7558</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0486" seq="1999-0486">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.</desc>
<refs>
<ref source="BUGTRAQ">19990420 AOL Instant Messenger URL Crash</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:aol-im.</comment>
<comment voter="Christey">XF:aol-im appears to be related to the problem discussed in
BUGTRAQ:19980224 AOL Instant Messanger Bug

This one is related to BUGTRAQ:19990420 AOL Instant Messenger URL Crash</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0487" seq="1999-0487">
<status>Entry</status>
<desc>The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-011.mspx">MS99-011</ref>
<ref source="XF">ie-dhtml-control</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0488" seq="1999-0488">
<status>Candidate</status>
<phase date="19991205">Modified</phase>
<desc>Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the &quot;cross frame&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref>
</refs>
<votes>
<accept count="2">Baker, Landfield</accept>
<modify count="2">Frech, Wall</modify>
<noop count="2">Christey, Ozancin</noop>
</votes>
<comments>
<comment voter="Frech">XF:ie-mshtml-crossframe</comment>
<comment voter="Wall">(source: MSKB:Q168485)</comment>
<comment voter="Christey">CVE-1999-0469 appears to be a duplicate; prefer this one over
that one, since this one has an MS advisory.  Confirm with
Microsoft that these are really duplicates.

Also review CVE-1999-0487, which appears to be a similar
bug.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0489" seq="1999-0489">
<status>Candidate</status>
<phase date="19991205">Modified</phase>
<desc>MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of &quot;untrusted scripted paste&quot; as described in MS:MS98-013.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp">MS99-015</ref>
</refs>
<votes>
<accept count="1">Levy</accept>
<modify count="1">Wall</modify>
<noop count="2">Baker, Ozancin</noop>
<recast count="1">Prosser</recast>
<reject count="1">Christey</reject>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">Wasn't Untrusted scripted paste MS98-015? I can find no mention of a
clipboard in either.
I cannot proceed on this one without further clarification.</comment>
<comment voter="Wall">(source: MS:MS99-012)</comment>
<comment voter="Prosser">agree with Andre here.  The Untrusted Scripted paste
vulnerability was originally addressed in MS98-015 and it is in the file
upload intrinsic control in which an attacker can paste the name of a file
on the target's drive in the control and a form submission would then send
that file from the attacked machine to the remote web site.  This one has
nothing to do with the clipboard.  What the advisory mentioned here,
MS99-012, does is replace the MSHTML parsing engine which is supposed to fix
the original Untrusted Scripted Paste issue and a variant, as well as the
two Cross-Frame variants and a privacy issue in IMG SRC.  
The vulnerability that allowed reading of a user's clipboard is the Forms
2.0 Active X control vulnerability discussed in MS99-01</comment>
<comment voter="Christey">The advisory should have been listed as MS99-012.  
CVE-1999-0468 describes the untrusted scripted paste problem
in MS99-012.</comment>
<comment voter="Frech">Pending response to guidance request. 12/6/01.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0490" seq="1999-0490">
<status>Candidate</status>
<phase date="19991205">Modified</phase>
<desc>MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref>
</refs>
<votes>
<accept count="2">Landfield, Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Ozancin</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:ie-scriplet-fileread</comment>
<comment voter="Christey">Duplicate of CVE-1999-0347?</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0491" seq="1999-0491">
<status>Entry</status>
<desc>The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9904202114070.6623-100000@smooth.Operator.org">19990420 Bash Bug</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt">CSSA-1999-008.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/119">119</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0492" seq="1999-0492">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.</desc>
<refs>
<ref source="BUGTRAQ">Apr23,1999</ref>
</refs>
<votes>
<accept count="3">Armstrong, Collins, Northcutt</accept>
<modify count="4">Baker, Blake, Frech, Shostack</modify>
<noop count="4">Christey, Cole, Landfield, Wall</noop>
<reviewing count="1">Ozancin</reviewing>
</votes>
<comments>
<comment voter="Shostack">isn't that what finger is supposed to do?</comment>
<comment voter="Landfield">Maybe we need a new category of &quot;unsafe system utilities and protocols&quot;</comment>
<comment voter="Blake">Ffingerd 1.19 allows remote attackers to differentiate valid and invalid
usernames on the target system based on its responses to finger queries.</comment>
<comment voter="Christey">CHANGEREF BUGTRAQ [canonicalize]
BUGTRAQ:19990423 Ffingerd privacy issues
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92488772121313&amp;w=2

Here's the nature of the problem.
(1) FFingerd allows users to decide not to be fingered,
printing a message &quot;That user does not want to be fingered&quot;
(2) If the fingered user does not exist, then FFingerd's
intended default is to print that the user does not
want to be fingered; however, the error message has a
period at the end.
Thus, ffingerd can allow someone to determine who valid users
on the server are, *in spite of* the intended functionality of
ffingerd itself.  Thus this exposure should be viewed in light
of the intended functionality of the application, as opposed
to the common usage of the finger protocol in general.

Also, the vendor posted a followup and said that a patch was
available.  See:
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92489375428016&amp;w=2</comment>
<comment voter="Baker">Vulnerability Reference (HTML)	Reference Type
http://www.securityfocus.com/archive/1/13422	Misc Defensive Info</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:ffinger-user-info(5393)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0493" seq="1999-0493">
<status>Entry</status>
<desc>rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/186&amp;type=0&amp;nav=sec.sba">00186</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-045.shtml">J-045</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/450">450</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0494" seq="1999-0494">
<status>Entry</status>
<desc>Denial of service in WinGate proxy through a buffer overflow in POP3.</desc>
<refs>
<ref source="XF">wingate-pop3-user-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0495" seq="1999-0495">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A remote attacker can gain access to a file system using ..  (dot dot) when accessing SMB shares.</desc>
<refs>
</refs>
<votes>
<accept count="6">Baker, Blake, Cole, Collins, Northcutt, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="4">Armstrong, Bishop, Landfield, Wall</noop>
<reviewing count="2">Christey, Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:nb-dotdotknown(837)
References would be appreciated. We've got no reference for this issue;
confidence rating is consequently low. </comment>
<comment voter="Levy">Some refernces:
http://www.securityfocus.com/archive/1/3894
http://www.securityfocus.com/archive/1/3533
http://www.securityfocus.com/archive/1/3535</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0496" seq="1999-0496">
<status>Entry</status>
<desc>A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q146965">Q146965</ref>
<ref source="XF">nt-getadmin</ref>
<ref source="XF">nt-getadmin-present</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0497" seq="1999-0497">
<status>Candidate</status>
<phase date="20040811">Modified</phase>
<desc>Anonymous FTP is enabled.</desc>
<refs>
</refs>
<votes>
<accept count="1">Shostack</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Frech">ftp-anon(52) at http://xforce.iss.net/static/52.php
ftp-anon2(543) at http://xforce.iss.net/static/543.php</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
<comment voter="Baker">DOn't know about this, but it may be the only easy way to allow access to data for some folks.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0498" seq="1999-0498">
<status>Candidate</status>
<phase date="19990925">Modified</phase>
<desc>TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.</desc>
<refs>
<ref source="CERT">CA-91.18.Active.Internet.tftp.Attacks</ref>
</refs>
<votes>
<accept count="3">Blake, Hill, Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:linux-tftp</comment>
<comment voter="Christey">XF:linux-tftp refers to CVE-1999-0183</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0499" seq="1999-0499">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>NETBIOS share information may be published through SNMP registry keys in NT.</desc>
<refs>
</refs>
<votes>
<accept count="5">Baker, Northcutt, Ozancin, Shostack, Wall</accept>
<modify count="1">Frech</modify>
<reject count="1">LeBlanc</reject>
</votes>
<comments>
<comment voter="Frech">Change wording to 'Windows NT.'
XF:snmp-netbios</comment>
<comment voter="LeBlanc">Share info can be obtained via SNMP queries, but I question
whether this is a vulnerability. The system can be configured not to do
this, and one may argue that SNMP itself is an insecure configuration.
Furthermore, the share information isn't published via registry keys -
the description could refer to more than one actual issue. SNMP is meant
to allow people to obtain information about systems. I'm willing to
discuss this with the rest of the board.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0501" seq="1999-0501">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A Unix account has a guessable password.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Northcutt, Shostack</accept>
<recast count="2">Frech, Meunier</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Guessable falls into the class of CVE-1999-0502, since I can guess a
default, null, etc. password.
Suggest changing to something like &quot;has an existing non-default password
that can be guessed.&quot;
I'm also including default passwords in this entry. 
In that vein, we show the following references:
XF:user-password
XF:passwd-username
XF:default-unix-sync
XF:default-unix-4dgifts
XF:default-unix-bin
XF:default-unix-daemon
XF:default-unix-lp
XF:default-unix-me
XF:default-unix-nuucp
XF:default-unix-root
XF:default-unix-toor
XF:default-unix-tour
XF:default-unix-tty
XF:default-unix-uucp</comment>
<comment voter="Christey">This candidate is affected by the CD:CF-PASS content decision,
which determines the appropriate level of abstraction to
use for password problems.  CD:CF-PASS needs to be accepted
by the Editorial Board before this candidate can be
converted into a CVE entry; the final version of CD:CF-PASS
may require using a different LOA than this candidate is
currently using.</comment>
<comment voter="CHANGE">[Meunier changed vote from ACCEPT to RECAST]</comment>
<comment voter="Meunier">This relates only to account password technology, so this candidate is
independent of the operating system, application, web site or other
application of this technology.  The appropriate (natural) level of
abstraction is therefore without specifying that it is for UNIX.
Change the description to &quot;An account has a guessable password other
than default, null, blank.&quot;  This should satisfy Andre's objection.

This Candidate should be merged with any candidate relating to
account password technology where &quot;Unix&quot; in the original description
can be replaced by something else.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0502" seq="1999-0502">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A Unix account has a default, null, blank, or missing password.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:passwd-blank
XF:no-pass
XF:dict
XF:sgi-accounts
XF:linux-caldera-lisa</comment>
<comment voter="Christey">This candidate is affected by the CD:CF-PASS content decision,
which determines the appropriate level of abstraction to
use for password problems.  CD:CF-PASS needs to be accepted
by the Editorial Board before this candidate can be
converted into a CVE entry; the final version of CD:CF-PASS
may require using a different LOA than this candidate is
currently using.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0503" seq="1999-0503">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A Windows NT local user or administrator account has a guessable password.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Note: I am assuming that this entry includes Windows 2000 accounts and
machine/service accounts listed in User Manager.
XF:nt-guess-admin
XF:nt-guess-user
XF:nt-guess-guest
XF:nt-guessed-operpwd
XF:nt-guessed-powerwd
XF:nt-guessed-disabled
XF:nt-guessed-backup
XF:nt-guessed-acctoper-pwd
XF:nt-adminuserpw
XF:nt-guestuserpw
XF:nt-accountuserpw
XF:nt-operator-userpw
XF:nt-service-user-pwd
XF:nt-server-oper-user-pwd
XF:nt-power-user-pwd
XF:nt-backup-operator-userpwd
XF:nt-disabled-account-userpwd</comment>
<comment voter="Christey">This candidate is affected by the CD:CF-PASS content decision,
which determines the appropriate level of abstraction to
use for password problems.  CD:CF-PASS needs to be accepted
by the Editorial Board before this candidate can be
converted into a CVE entry; the final version of CD:CF-PASS
may require using a different LOA than this candidate is
currently using.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0504" seq="1999-0504">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A Windows NT local user or administrator account has a default, null, blank, or missing password.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:nt-guestblankpw
XF:nt-adminblankpw
XF:nt-adminnopw
XF:nt-usernopw
XF:nt-guestnopw
XF:nt-accountblankpw
XF:nt-nopw
XF:nt-operator-blankpwd
XF:nt-server-oper-blank-pwd
XF:nt-power-user-blankpwd
XF:nt-backup-operator-blankpwd
XF:nt-disabled-account-blankpwd</comment>
<comment voter="Christey">This candidate is affected by the CD:CF-PASS content decision,
which determines the appropriate level of abstraction to
use for password problems.  CD:CF-PASS needs to be accepted
by the Editorial Board before this candidate can be
converted into a CVE entry; the final version of CD:CF-PASS
may require using a different LOA than this candidate is
currently using.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0505" seq="1999-0505">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A Windows NT domain user or administrator account has a guessable password.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:nt-guessed-domain-userpwd
XF:nt-guessed-domain-guestpwd
XF:nt-guessed-domain-adminpwd
XF:nt-domain-userpwd
XF:nt-domain-admin-userpwd
XF:nt-domain-guest-userpwd
XF:win2k-certpub-usrpwd
XF:win2k-dhcpadm-usrpwd
XF:win2k-dnsadm-usrpwd
XF:win2k-entadm-usrpwd
XF:win2k-schema-usrpwd
XF:win2k-guessed-certpub
XF:win2k-guessed-dhcpadm
XF:win2k-guessed-dnsadm
XF:win2k-guessed-entadm
XF:win2k-guessed-schema</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0506" seq="1999-0506">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A Windows NT domain user or administrator account has a default, null, blank, or missing password.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:nt-domain-admin-blankpwd
XF:nt-domain-admin-nopwd
XF:nt-domain-guest-blankpwd
XF:nt-domain-guest-nopwd
XF:nt-domain-user-blankpwd
XF:nt-domain-user-nopwd
XF:win2k-certpub-blnkpwd
XF:win2k-dhcpadm-blnkpwd
XF:win2k-dnsadm-blnkpwd
XF:win2k-entadm-blnkpwd
XF:win2k-schema-blnkpwd</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0507" seq="1999-0507">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>An account on a router, firewall, or other network device has a guessable password.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:firewall-tisopen
XF:firewall-raptoropen
XF:firewall-msopen
XF:firewall-checkpointopen
XF:firewall-ciscoopen</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0508" seq="1999-0508">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>An account on a router, firewall, or other network device has a default, null, blank, or missing password.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">Note: Because the distinction between network hardware and software is not
distinct, 
the term 'network device' was liberally interpreted. Feel free to reject any
of the
below terms.
XF:default-netranger
XF:cayman-gatorbox
XF:breezecom-default-passwords
XF:default-portmaster
XF:wingate-unpassworded
XF:netopia-unpassworded
XF:default-bay-switches
XF:motorola-cable-default-pass
XF:default-flowpoint
XF:qms-2060-no-root-password
XF:avirt-ras-password
XF:webtrends-rtp-serv-install-password
XF:cisco-bruteforce
XF:cisco-bruteadmin
XF:sambar-server-defaults
XF:management-pfcuser
XF:http-cgi-wwwboard-default</comment>
<comment voter="Christey">DELREF XF:avirt-ras-password - does not fit CVE-1999-0508.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0509" seq="1999-0509">
<status>Candidate</status>
<phase date="20000114">Modified</phase>
<desc>Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="CERT">CA-96.11</ref>
</refs>
<votes>
<accept count="2">Northcutt, Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">What is the right level of abstraction to use here?  Should
we combine all possible interpreters into a single entry,
or have a different entry for each one?  I've often seen
Perl separated from other interpreters - is it included
by default in some Windows web server configurations?</comment>
<comment voter="Christey">Add tcsh, zsh, bash, rksh, ksh, ash, to support search.</comment>
<comment voter="Frech">XF:http-cgi-vuln(146)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0510" seq="1999-0510">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A router or firewall allows source routed packets from arbitrary hosts.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:source-routing</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0511" seq="1999-0511">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>IP forwarding is enabled on a machine which is not a router or firewall.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:ip-forwarding</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0512" seq="1999-0512">
<status>Candidate</status>
<phase date="20020427">Modified</phase>
<desc>A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:smtp-sendmail-relay(210)
XF:ntmail-relay(2257)
XF:exchange-relay(3107) (also assigned to CVE-1999-0682)
XF:smtp-relay-uucp(3470)
XF:sco-sendmail-spam(4342)
XF:sco-openserver-mmdf-spam(4343)
XF:lotus-domino-smtp-mail-relay(6591)
XF:win2k-smtp-mail-relay(6803)
XF:cobalt-poprelayd-mail-relay(6806)

Candidate implicitly may refer to relaying settings enabled by default, or
the bypass/circumvention of relaying. Both interpretations were used in
assigning this candidate.</comment>
<comment voter="Christey">The intention of this candidate is to cover configurations in
which the admin has explicitly enabled relaying.  Other cases
in which the application *intends* to prvent relaying, but
there is some specific input that bypasses/tricks it, count
as vulnerabilities (or exposures?) and as such would be
assigned different numbers.

http://www.sendmail.org/~ca/email/spam.html seems like a good
general resource, as does ftp://ftp.isi.edu/in-notes/rfc2505.txt</comment>
<comment voter="Christey">I changed the description to make it more clear that the issue
is that of explicit configuration, as opposed to being the
result of a vulnerability.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0513" seq="1999-0513">
<status>Entry</status>
<desc>ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.</desc>
<refs>
<ref source="CERT">CA-98.01.smurf</ref>
<ref source="FREEBSD">FreeBSD-SA-98:06</ref>
<ref source="XF">smurf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0514" seq="1999-0514">
<status>Entry</status>
<desc>UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.</desc>
<refs>
<ref source="XF">fraggle</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0515" seq="1999-0515">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<modify count="1">Frech</modify>
<reject count="1">Shostack</reject>
</votes>
<comments>
<comment voter="Shostack">Overly broad</comment>
<comment voter="Frech">XF:rsh-equiv(111)</comment>
<comment voter="Baker">Since this is unrestricted trust, I agree this is a problem</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0516" seq="1999-0516">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>An SNMP community name is guessable.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:snmp-get-guess
XF:snmp-set-guess
XF:sol-hidden-commstr
XF:hpov-hidden-snmp-comm</comment>
<comment voter="Christey">This candidate is affected by the CD:CF-PASS content decision,
which determines the appropriate level of abstraction to
use for password problems.  CD:CF-PASS needs to be accepted
by the Editorial Board before this candidate can be
converted into a CVE entry; the final version of CD:CF-PASS
may require using a different LOA than this candidate is
currently using.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0517" seq="1999-0517">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>An SNMP community name is the default (e.g. public), null, or missing.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:nt-snmp
XF:snmp-comm
XF:snmp-set-any
XF:snmp-get-public
XF:snmp-set-public
XF:snmp-get-any</comment>
<comment voter="Christey">This candidate is affected by the CD:CF-PASS content decision,
which determines the appropriate level of abstraction to
use for password problems.  CD:CF-PASS needs to be accepted
by the Editorial Board before this candidate can be
converted into a CVE entry; the final version of CD:CF-PASS
may require using a different LOA than this candidate is
currently using.</comment>
<comment voter="Christey">Consider adding BID:2112</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0518" seq="1999-0518">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A NETBIOS/SMB share password is guessable.</desc>
<refs>
</refs>
<votes>
<accept count="5">Baker, LeBlanc, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">Change description term to NetBIOS.
XF:nt-netbios-perm
XF:sharepass
XF:win95-smb-password
XF:nt-netbios-dict</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0519" seq="1999-0519">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A NETBIOS/SMB share password is the default, null, or missing.</desc>
<refs>
</refs>
<votes>
<accept count="5">Baker, LeBlanc, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">Change description term to NetBIOS.
XF:decod-smb-password-empty
XF:nt-netbios-everyoneaccess
XF:nt-netbios-guestaccess
XF:nt-netbios-allaccess
XF:nt-netbios-open
XF:nt-netbios-write
XF:nt-netbios-shareguest
XF:nt-writable-netbios
XF:nt-netbios-everyoneaccess-printer
XF:nt-netbios-share-print-guest</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0520" seq="1999-0520">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>A system-critical NETBIOS/SMB share has inappropriate access control.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<recast count="1">Northcutt</recast>
<reject count="1">LeBlanc</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Northcutt">I think we need to enumerate the shares and or the access control</comment>
<comment voter="Christey">One question is, what is &quot;inappropriate&quot;?  It's probably
very dependent on the policy of the enterprise on which
this is found.  And should writable shares be different
from readable shares?  (Or file systems, mail spools, etc.)
Yes, the impact may be different, but we could have a
large number of entries for each possible type of access.
A content decision (CD:CF-DATA) needs to be reviewed
and accepted by the Editorial Board in order to resolve
this question.</comment>
<comment voter="LeBlanc">Unacceptably vague - agree with Christey's comments.</comment>
<comment voter="Frech">associated to:
XF:nt-netbios-everyoneaccess(1)
XF:nt-netbios-guestaccess(2)
XF:nt-netbios-allaccess(3)
XF:nt-netbios-open(15)
XF:nt-netbios-write(19)
XF:nt-netbios-shareguest(20)
XF:nt-writable-netbios(26)
XF:nb-rootshare(393)
XF:decod-smb-password-empty(2358)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0521" seq="1999-0521">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>An NIS domain name is easily guessable.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:nis-dom</comment>
<comment voter="Christey">Consider http://www.cert.org/advisories/CA-1992-13.html
as well as ftp://ciac.llnl.gov/pub/ciac/bulletin/c-fy92/c-25.ciac-sunos-nis-patch</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0522" seq="1999-0522">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.</desc>
<refs>
<ref source="CERT">CA-96.10</ref>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<noop count="1">Christey</noop>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">Why not say world readable, this is what you do further down in the
file (world exportable in CVE-1999-0554)</comment>
<comment voter="Christey">ADDREF AUSCERT:AA-96.02</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0523" seq="1999-0523">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>ICMP echo (ping) is allowed from arbitrary hosts.</desc>
<refs>
</refs>
<votes>
<modify count="1">Meunier</modify>
<noop count="1">Baker</noop>
<reject count="2">Frech, Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">(Though I sympathize with this one :)</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to REJECT]</comment>
<comment voter="Frech">Ping is a utility that can be run on demand; ICMP echo is a
message 
type. As currently worded, this candidate seems as if an arbitrary
host 
is vulnerable because it is capable of running an arbitrary program
or
function (in this case, ping/ICMP echo). There are many
programs/functions that 
'shouldn't' be on a computer, from a security admin's perspective.
Even if this
were a vulnerability, it would be impacted by CD-HIGHCARD.</comment>
<comment voter="Meunier">Every ICMP message type presents a vulnerability or an
exposure, if access is not controlled.  By that I mean not only those
in RFC 792, but also those in RFC 1256, 950, and more.  I think that
the description should be changed to &quot;ICMP messages are acted upon
without any access control&quot;.  ICMP is an error and debugging protocol.
We complain about vendors leaving testing backdoors in their programs.
ICMP is the equivalent for TCP/IP.  ICMP should be in the dog house,
unless you are trying to troubleshoot something.  MTU discovery is
just a performance tweak -- it's not necessary.  I don't know of any
ICMP message type that is necessary if the network is functional.
Limited logging of ICMP messages could be useful, but acting upon them
and allowing the modification of routing tables, the behavior of the
TCP/IP stack, etc... without any form of authentication is just crazy.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0524" seq="1999-0524">
<status>Candidate</status>
<phase date="20070716">Modified</phase>
<desc>ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.</desc>
<refs>
<ref source="MISC" url="http://descriptions.securescout.com/tc/11010">http://descriptions.securescout.com/tc/11010</ref>
<ref source="MISC" url="http://descriptions.securescout.com/tc/11011">http://descriptions.securescout.com/tc/11011</ref>
<ref source="MISC" url="http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434">http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434</ref>
<ref source="OSVDB" url="http://www.osvdb.org/95">95</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/306">icmp-netmask(306)</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/322">icmp-timestamp(322)</ref>
</refs>
<votes>
<modify count="3">Baker, Frech, Meunier</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Frech">XF:icmp-timestamp
XF:icmp-netmask</comment>
<comment voter="Meunier">If this is not merged with 1999-0523 as I commented for that
CVE, then the description should be changed to &quot;ICMP messages of types
13 and 14 (timestamp request and reply) and 17 and 18 (netmask request
and reply) are acted upon without any access control&quot;.  It's a more
precise and correct language.  I believe that this is a valid CVE
entry (it's a common source of vulnerabilities or exposures) even
though I see that the inferred action was &quot;reject&quot;.  Knowing the time
of a host also allows attacks against random number generators that
are seeded with the current time.  I want to push to have it accepted.</comment>
<comment voter="Baker">I agree with the description changes suggested by Pascal</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0525" seq="1999-0525">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>IP traceroute is allowed from arbitrary hosts.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Frech">XF:traceroute</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0526" seq="1999-0526">
<status>Entry</status>
<desc>An X server's access control is disabled (e.g. through an &quot;xhost +&quot; command) and allows anyone to connect to the server.</desc>
<refs>
<ref source="XF">xcheck-keystroke</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/704969">VU#704969</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0527" seq="1999-0527">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>The permissions for system-critical data in an anonymous FTP account are inappropriate.  For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as &quot;ls&quot; can be overwritten.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Northcutt, Wall</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Northcutt">That that starts to get specific :)</comment>
<comment voter="Frech">ftp-writable-directory(6253)
ftp-write(53)
&quot;writeable&quot; in the description should be &quot;writable.&quot; </comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0528" seq="1999-0528">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Meunier, Northcutt</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">possibly XF:nisd-dns-fwd-check</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:firewall-external-packet-forwarding(8372)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0529" seq="1999-0529">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.</desc>
<refs>
</refs>
<votes>
<accept count="1">Frech</accept>
<modify count="2">Baker, Meunier</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">I have seen ISPs &quot;assign&quot; private addresses within their domain</comment>
<comment voter="Meunier">A border router or firewall forwards packets that claim to come from IANA
reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x,
etc, outside of their area of validity.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to ACCEPT]</comment>
<comment voter="Baker">I think the description should be modified to say they accept this type of traffic from an interface not residing on private/reserved network.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0530" seq="1999-0530">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A system is operating in &quot;promiscuous&quot; mode which allows it to perform packet sniffing.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<modify count="1">Frech</modify>
<reject count="1">Shostack</reject>
</votes>
<comments>
<comment voter="Frech">XF:etherstatd(264)
XF:sniffer-attack(778) 
XF:decod-packet-capture-remote(1072)
XF:netmon-running(1448)
XF:netxray3-probe(1450)
XF:sol-snoop-getquota-bo(3670) (also assigned to CVE-1999-0974)</comment>
<comment voter="Baker">Does pose a problem in non-switched environments</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0531" seq="1999-0531">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO.&quot;</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
<recast count="1">Shostack</recast>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Shostack">I think expn != vrfy, help, esmtp.</comment>
<comment voter="Frech">XF:lotus-domino-esmtp-bo(4499) (also assigned to CVE-2000-0452 and
CVE-2000-1046)
XF:smtp-expn(128)
XF:smtp-vrfy(130)
XF:smtp-helo-bo(886)
XF:smtp-vrfy-bo(887)
XF:smtp-expn-bo(888)
XF:slmail-vrfyexpn-overflow(1721)
XF:smtp-ehlo(323)

Perhaps add RCPT? If so, add XF:smtp-rcpt(1928)</comment>
<comment voter="Christey">XF:smtp-vrfy(130) ?</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0532" seq="1999-0532">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A DNS server allows zone transfers.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">(With split DNS implementations this is quite appropriate)</comment>
<comment voter="Frech">XF:dns-zonexfer</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0533" seq="1999-0533">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A DNS server allows inverse queries.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">(rule of thumb)</comment>
<comment voter="Frech">XF:dns-iquery</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0534" seq="1999-0534">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.</desc>
<refs>
</refs>
<votes>
<accept count="5">Baker, Christey, Ozancin, Shostack, Wall</accept>
<modify count="2">Frech, Northcutt</modify>
</votes>
<comments>
<comment voter="Northcutt">If we are going to write a laundry list put access to the scheduler in it.</comment>
<comment voter="Christey">The list of privileges is very useful for lookup.</comment>
<comment voter="Frech">XF:nt-create-token
XF:nt-replace-token
XF:nt-lock-memory
XF:nt-increase-quota
XF:nt-unsol-input
XF:nt-act-system
XF:nt-create-object
XF:nt-sec-audit
XF:nt-add-workstation
XF:nt-manage-log
XF:nt-take-owner
XF:nt-load-driver
XF:nt-profile-system
XF:nt-system-time
XF:nt-single-process
XF:nt-increase-priority
XF:nt-create-pagefile
XF:nt-backup
XF:nt-restore
XF:nt-debug
XF:nt-system-env
XF:nt-remote-shutdown</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0535" seq="1999-0535">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.</desc>
<refs>
</refs>
<votes>
<accept count="2">Shostack, Wall</accept>
<modify count="2">Baker, Frech</modify>
<recast count="2">Northcutt, Ozancin</recast>
</votes>
<comments>
<comment voter="Northcutt">inappropriate implies there is appropriate.  As a guy who has been
monitoring
networks for years I have deep reservations about justiying the existance
of any fixed cleartext password. For appropriate to exist, some &quot;we&quot; would 
have to establish some criteria for appropriate passwords.</comment>
<comment voter="Baker">Perhaps this could be re-worded a bit.  The CVE CVE-1999-00582
specifies &quot;...settings for lockouts&quot;.  To remain consistent with the
other, maybe it should specify &quot;...settings for passwords&quot; I think
most people would agree that passwords should be at least 8
characters; contain letters (upper and lowercase), numbers and at
least one non-alphanumeric; should only be good a limited time 30-90
days; and should not contain character combinations from user's prior
2 or 3 passwords.
Suggested rewrite - 
A Windows NT account policy does not enforce reasonable minimum
security-critical settings for passwords, e.g. passwords of sufficient
length, periodic required password changes, or new password uniqueness</comment>
<comment voter="Ozancin">What is appropriate?</comment>
<comment voter="Frech">XF:nt-autologonpwd
XF:nt-pwlen
XF:nt-maxage
XF:nt-minage
XF:nt-pw-history
XF:nt-user-pwnoexpire
XF:nt-unknown-pwdfilter
XF:nt-pwd-never-expire
XF:nt-pwd-nochange
XF:nt-pwdcache-enable
XF:nt-guest-change-passwords</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0537" seq="1999-0537">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="1">Baker</noop>
<recast count="1">Frech</recast>
<reject count="1">LeBlanc</reject>
</votes>
<comments>
<comment voter="Frech">Good candidate for dot notation.
XF:nav-java-enabled
XF:nav-javascript-enabled
XF:ie-active-content
XF:ie-active-download
XF:ie-active-scripting
XF:ie-activex-execution
XF:ie-java-enabled
XF:netscape-javascript
XF:netscape-java
XF:zone-active-scripting
XF:zone-activex-execution
XF:zone-desktop-install
XF:zone-low-channel
XF:zone-file-download
XF:zone-file-launch
XF:zone-java-scripting
XF:zone-low-java
XF:zone-safe-scripting
XF:zone-unsafe-scripting</comment>
<comment voter="LeBlanc">Not a vulnerability. These are just checks for configuration
settings that a user might have changed. I understand need to increase
number of checks in a scanning product, but don't feel like these belong
in CVE. Scanner vendors could argue that these entries are needed to
keep a common language.</comment>
<comment voter="Baker">Not sure about whether we should bother to include this type issue or not.  It does provide a stepping stone for further actions, but in and of itself it isn't a specific vulnerability.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0539" seq="1999-0539">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A trust relationship exists between two Unix hosts.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="2">Northcutt, Shostack</reject>
</votes>
<comments>
<comment voter="Northcutt">Too non specific</comment>
<comment voter="Frech">XF:trusted-host(341)
XF:trust-remote-same(717)
XF:trust-remote-root(718)
XF:trust-remote-nonroot(719)
XF:trust-remote-any(720)
XF:trust-other-host(723)
XF:trust-all-nonroot(726)
XF:trust-any-remote(727)
XF:trust-local-acct(728)
XF:trust-local-any(729)
XF:trust-local-nonroot(730)
XF:trust-all-hosts(731)
XF:nt-trusted-domain(1284)
XF:rsagent-trusted-domainadded(1588)
XF:trust-remote-user(2955)
XF:user-trust-hosts(3074)
XF:user-trust-other-host(3077)
XF:user-trust-remote-account(3079)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0541" seq="1999-0541">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>A password for accessing a WWW URL is guessable.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Meunier, Northcutt, Shostack</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:http-password</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0546" seq="1999-0546">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>The Windows NT guest account is enabled.</desc>
<refs>
</refs>
<votes>
<accept count="5">Baker, Northcutt, Ozancin, Shostack, Wall</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:nt-guest-account</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0547" seq="1999-0547">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>An SSH server allows authentication through the .rhosts file.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Shostack</accept>
<modify count="1">Frech</modify>
<noop count="1">Northcutt</noop>
</votes>
<comments>
<comment voter="Frech">XF:sshd-rhosts(315)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0548" seq="1999-0548">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A superfluous NFS server is running, but it is not importing or exporting any file systems.</desc>
<refs>
</refs>
<votes>
<accept count="1">Shostack</accept>
<noop count="1">Baker</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0549" seq="1999-0549">
<status>Candidate</status>
<phase date="19990630">Proposed</phase>
<desc>Windows NT automatically logs in an administrator upon rebooting.</desc>
<refs>
</refs>
<votes>
<accept count="1">Hill</accept>
<modify count="3">Blake, Frech, Ozancin</modify>
<noop count="1">Wall</noop>
<reject count="1">Baker</reject>
</votes>
<comments>
<comment voter="Wall">Don't know what this is.  Don't think it is a vulnerability and would
initially reject.  This is different than just renaming the
administrator account.</comment>
<comment voter="Frech">Would appreciate more information on this one, as in a reference.</comment>
<comment voter="Blake">Reference: XF:nt-autologin</comment>
<comment voter="Ozancin">Needs more detail</comment>
<comment voter="Baker">I tried to find the XF:nt-autologin reference, and got no matching records from their search engine.
No refs, no details, should reject</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:nt-autologon(5)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0550" seq="1999-0550">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A router's routing tables can be obtained from arbitrary hosts.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">Don't you mean obtained by arbitrary hosts</comment>
<comment voter="Frech">XF:routed
XF:decod-rip-entry
XF:rip</comment>
<comment voter="Baker">Concur with this as a security issue</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0551" seq="1999-0551">
<status>Entry</status>
<desc>HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9804-078">HPSBUX9804-078</ref>
<ref source="XF">hp-openmail</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0554" seq="1999-0554">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>NFS exports system-critical data to the world, e.g. / or a password file.</desc>
<refs>
</refs>
<votes>
<accept count="2">Northcutt, Wall</accept>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">A content decision (CD:CF-DATA) needs to be reviewed
and accepted by the Editorial Board in order to resolve
this question.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0555" seq="1999-0555">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A Unix account with a name other than &quot;root&quot; has UID 0, i.e. root privileges.</desc>
<refs>
</refs>
<votes>
<noop count="1">Baker</noop>
<reject count="2">Northcutt, Shostack</reject>
</votes>
<comments>
<comment voter="Northcutt">This is very bogus</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0556" seq="1999-0556">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Two or more Unix accounts have the same UID.</desc>
<refs>
</refs>
<votes>
<noop count="2">Baker, Christey</noop>
<reject count="2">Northcutt, Shostack</reject>
</votes>
<comments>
<comment voter="Christey">XF:duplicate-uid(876)</comment>
<comment voter="Christey">Add terms &quot;duplicate&quot; and &quot;user ID&quot; to facilitate search.
ftp://ftp.auscert.org.au/pub/auscert/papers/unix_security_checklist</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0559" seq="1999-0559">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>A system-critical Unix file or directory has inappropriate permissions.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<recast count="2">Northcutt, Shostack</recast>
</votes>
<comments>
<comment voter="Northcutt">Writable other than by root/bin/wheelgroup?</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0560" seq="1999-0560">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>A system-critical Windows NT file or directory has inappropriate permissions.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">I think we should specify these</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0561" seq="1999-0561">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>IIS has the #exec function enabled for Server Side Include (SSI) files.</desc>
<refs>
</refs>
<votes>
<noop count="2">Baker, Northcutt</noop>
<recast count="1">Shostack</recast>
<reject count="1">LeBlanc</reject>
</votes>
<comments>
<comment voter="LeBlanc">Does not meet definition of a vulnerability. This function is
just enabled. You can turn it off if you want. if you trust the people
putting up your web pages, this isn't a problem. If you don't, this is
just one of many things you need to change.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0562" seq="1999-0562">
<status>Candidate</status>
<phase date="20061101">Modified</phase>
<desc>The registry in Windows NT can be accessed remotely by users who are not administrators.</desc>
<refs>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1023">oval:org.mitre.oval:def:1023</ref>
</refs>
<votes>
<accept count="4">Baker, Ozancin, Shostack, Wall</accept>
<modify count="1">Frech</modify>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">This isn't all or nothing, users may be allowed to access part of the
registry.</comment>
<comment voter="Frech">XF:nt-winreg-all
XF:nt-winreg-net</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0564" seq="1999-0564">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Shostack</accept>
<noop count="1">Northcutt</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0565" seq="1999-0565">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A Sendmail alias allows input to be piped to a program.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<noop count="1">Baker</noop>
<recast count="1">Shostack</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Shostack">Is this a default alias?  Is my .procmailrc an instance of this?</comment>
<comment voter="Christey">It is not entirely clear whether the simple fact that an alias
pipes into a program should be considered a vulnerability.  It
all depends on the behavior of that particular program.  This
is one of a number of configuration-related issues from the
&quot;draft&quot; CVE that came from vulnerability scanners.  In
general, when we get to general configuration and &quot;policy,&quot;
it becomes more difficult to use the current CVE model to
represent them.  So at the very least, this candidate (and
similar ones) should be given close consideration and
discussion before being added to the official CVE list.

Because this candidate is related to general configuration
issues, and we have not completely determined how to handle
such issues in CVE, this candidate cannot be promoted to an
official CVE entry until such issues are resolved.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0566" seq="1999-0566">
<status>Entry</status>
<desc>An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.</desc>
<refs>
<ref source="XF">ibm-syslogd</ref>
<ref source="XF">syslog-flood</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0568" seq="1999-0568">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>rpc.admind in Solaris is not running in a secure mode.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<noop count="2">Baker, Christey</noop>
<recast count="2">Dik, Shostack</recast>
</votes>
<comments>
<comment voter="Shostack">are there secure modes?</comment>
<comment voter="Dik">Several:
1) there is no &quot;rpc.admind&quot; daemon.
there used to be a &quot;admind&quot; RPC daemon (100087/10)
and there's now an &quot;sadmind&quot; daemon (100232/10)
The switch over was somewhere around Solaris 2.4.
2) Neither defaults to &quot;secure mode&quot;
3) secure mode is &quot;using secure RPC&quot; which does
proper over the wire authentication by specifying
the &quot;-S 2&quot; option in inetd.conf
(security level 2)</comment>
<comment voter="Christey">XF:rpc-admind(626)
http://xforce.iss.net/static/626.php
MISC:http://pulhas.org/xploitsdb/mUNIXes/admind.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0569" seq="1999-0569">
<status>Candidate</status>
<phase date="19991130">Modified</phase>
<desc>A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="2">Baker, Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">I do this intentionally somethings in high content directories</comment>
<comment voter="Christey">XF:http-noindex(90) ?</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0570" seq="1999-0570">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Wall</reject>
</votes>
<comments>
<comment voter="Northcutt">Here we are crossing into the best practices arena again.  However since
passfilt does establish a measurable standard and since we aren't the
ones defining the stanard, simply saying it should be employed I will
vote for this.  </comment>
<comment voter="Frech">XF:nt-passfilt-not-inst(1308)
XF:nt-passfilt-not-found(1309)</comment>
<comment voter="Christey">Consider MSKB:Q161990 and MSKB:Q151082</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0571" seq="1999-0571">
<status>Candidate</status>
<phase date="20020312">Modified</phase>
<desc>A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.</desc>
<refs>
<ref source="BUGTRAQ">Feb5,1999</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Northcutt</noop>
</votes>
<comments>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:ascend-config-kill(889)
XF:cisco-ios-crash(1238)
XF:webramp-remote-access(1670)
XF:ascom-timeplex-debug(1824)
XF:netopia-unpassworded(1850)
XF:cisco-web-crash(1886)
XF:cisco-router-commands(1951)
XF:motorola-cable-default-pass(2002)
XF:default-flowpoint(2091)
XF:netgear-router-idle-dos(4003)
XF:cisco-cbos-telnet(4251)
XF:routermate-snmp-community(4290)
XF:cayman-router-dos(4479)
XF:wavelink-authentication(5185)
XF:ciscosecure-ldap-bypass-authentication(5274)
XF:foundry-firmware-telnet-dos(5514)
XF:netopia-view-system-log(5536)
XF:cisco-webadmin-remote-dos(5595)
XF:cisco-cbos-web-access(5626)
XF:netopia-telnet-dos(6001)
XF:cisco-sn-gain-access(6827)
XF:cayman-dsl-insecure-permissions(6841)
XF:linksys-etherfast-reveal-passwords(6949)
XF:zyxel-router-default-password(6968)
XF:cisco-cbos-web-config(7027)
XF:prestige-wan-bypass-filter(7146)</comment>
<comment voter="Christey">I changed the description to make it more explicit that this
candidate is about router configuration, as opposed to
vulnerabilities that accidentally make a configuration
service accessible to anyone.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0572" seq="1999-0572">
<status>Candidate</status>
<phase date="20041017">Modified</phase>
<desc>.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Ozancin, Shostack, Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Northcutt</noop>
</votes>
<comments>
<comment voter="Northcutt">I don't quite get what this means, sorry</comment>
<comment voter="Frech">XF:nt-regfile(178)</comment>
<comment voter="Christey">MISC:http://security-archive.merton.ox.ac.uk/nt-security-199902/0087.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0575" seq="1999-0575">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.</desc>
<refs>
</refs>
<votes>
<accept count="4">Christey, Ozancin, Shostack, Wall</accept>
<modify count="1">Frech</modify>
<recast count="2">Baker, Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">It isn't a great truth that you should enable all or the above, if you
do you potentially introduce a vulnerbility of filling up the file
system with stuff you will never look at.</comment>
<comment voter="Ozancin">It is far less interesting what a user does successfully that what they
attempt and fail at.</comment>
<comment voter="Christey">The list of event types is very useful for lookup.</comment>
<comment voter="Frech">XF:nt-system-audit
XF:nt-logon-audit
XF:nt-object-audit
XF:nt-privil-audit
XF:nt-process-audit
XF:nt-policy-audit
XF:nt-account-audit</comment>
<comment voter="CHANGE">[Baker changed vote from REVIEWING to RECAST]</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0576" seq="1999-0576">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Shostack, Wall</accept>
<modify count="2">Frech, Ozancin</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">1.) Too general are we ready to state what the security-critical files
and directories are
2.) Does Ataris, Windows CE, PalmOS, Linux have such a capability</comment>
<comment voter="Ozancin">Some files and directories are clearly understood to be critical. Others are
unclear. We need to clarify that critical is.</comment>
<comment voter="Frech">XF:nt-object-audit</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0577" seq="1999-0577">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.</desc>
<refs>
</refs>
<votes>
<accept count="2">Shostack, Wall</accept>
<modify count="3">Baker, Frech, Ozancin</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Ozancin">It is far less interesting what a user does successfully that what they
attempt and fail at.
Perhaps only failure should be logged.</comment>
<comment voter="Frech">XF:nt-object-audit</comment>
<comment voter="CHANGE">[Baker changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Baker">Failure on non-critical files is what should be monitored.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0578" seq="1999-0578">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Ozancin, Shostack, Wall</accept>
<modify count="1">Frech</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Ozancin">with reservation
Again what is defined as critical</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:nt-object-audit(228)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0579" seq="1999-0579">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Shostack, Wall</accept>
<modify count="2">Frech, Ozancin</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Ozancin">Again only failure may be of interest. It would be impractical to wad
through the incredibly large amount of logging that this would generate. It
could overwhelm log entries that you might find interesting.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:nt-object-audit(228)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0580" seq="1999-0580">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="1">Baker</noop>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">I think we can define appropriate, take a look at the nt security .pdf
and see if you can't see a way to phrase specific keys in a way that
defines inappropriate.</comment>
<comment voter="Baker">This is way vague...</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0581" seq="1999-0581">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="1">Baker</noop>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">I think we can define appropriate, take a look at the nt security .pdf
and see if you can't see a way to phrase specific keys in a way that
defines inappropriate.</comment>
<comment voter="Baker">way too vague</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0582" seq="1999-0582">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.</desc>
<refs>
</refs>
<votes>
<accept count="3">Ozancin, Shostack, Wall</accept>
<modify count="2">Baker, Frech</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">The definition is?</comment>
<comment voter="Baker">Maybe a rewording of this one too.  I think most people would agree on
some &quot;minimum&quot; policies like 3-5 bad attempts lockout for an hour or
until the administrator unlocks the account.
Suggested rewrite -
A Windows NT account policy does not enforce reasonable minimum
security-critical settings for lockouts, e.g. lockout duration,
lockout after bad logon attempts, etc.</comment>
<comment voter="Ozancin">with reservations
What is appropriate?</comment>
<comment voter="Frech">XF:nt-thres-lockout
XF:nt-lock-duration
XF:nt-lock-window
XF:nt-perm-lockout
XF:lockout-disabled</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0583" seq="1999-0583">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>There is a one-way or two-way trust relationship between Windows NT domains.</desc>
<refs>
</refs>
<votes>
<noop count="2">Baker, Christey</noop>
<reject count="2">Northcutt, Shostack</reject>
</votes>
<comments>
<comment voter="Christey">XF:nt-trusted-domain(1284)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0584" seq="1999-0584">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A Windows NT file system is not NTFS.</desc>
<refs>
</refs>
<votes>
<accept count="2">Northcutt, Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
</votes>
<comments>
<comment voter="Wall">NTFS partition provides the security.  This could be re-worded
to &quot;A Windows NT file system is FAT&quot; since it is either NTFS or FAT
and FAT is less secure.</comment>
<comment voter="Frech">XF:nt-filesys(195)</comment>
<comment voter="Christey">MSKB:Q214579
MSKB:Q214579
http://support.microsoft.com/support/kb/articles/Q100/1/08.ASP</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0585" seq="1999-0585">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>A Windows NT administrator account has the default name of Administrator.</desc>
<refs>
</refs>
<votes>
<accept count="1">Ozancin</accept>
<modify count="1">Frech</modify>
<reject count="3">Baker, Northcutt, Shostack</reject>
<reviewing count="1">Wall</reviewing>
</votes>
<comments>
<comment voter="Wall">Some sources say this is not a vulnerability, but a warning.  It just
slows down the search for the admin account (SID = 500) which can
always be found.</comment>
<comment voter="Northcutt">I change this on all NT systems I am responsible for, but is
root a vulnerability?</comment>
<comment voter="Baker">There are ways to identify the administrator account anyway, so this
is only a minor delay to someone that is knowledgeable.  This, in and
of itself, doesn't really strike me as a vulnerability, anymore than
the root account on a Unix box.</comment>
<comment voter="Shostack">(there is no way to hide the account name today)</comment>
<comment voter="Frech">XF:nt-adminexists</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0586" seq="1999-0586">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A network service is running on a nonstandard port.</desc>
<refs>
</refs>
<votes>
<noop count="1">Baker</noop>
<recast count="1">Shostack</recast>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Shostack">Might be acceptable if clearer; is that a standard service on a
non-standard port, or any service on an unassigned port?</comment>
<comment voter="Baker">It might actually be an enhancement rather than a problem to run a service on a non-standard port</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0587" seq="1999-0587">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="1">Baker</noop>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">While I would accept this for Unix, I am not sure this applies to NT,
VMS, palm pilots, or commodore 64</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0588" seq="1999-0588">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A filter in a router or firewall allows unusual fragmented packets.</desc>
<refs>
</refs>
<votes>
<modify count="2">Baker, Frech</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Northcutt">I want to vote to accept this one, but unusual is a shade broad.</comment>
<comment voter="Frech">XF:nt-rras
XF:cisco-fragmented-attacks
XF:ip-frag</comment>
<comment voter="Baker">Perhaps we should use the word abnormally fragmented or some other descriptor.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0589" seq="1999-0589">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>A system-critical Windows NT registry key has inappropriate permissions.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="1">Baker</noop>
<recast count="2">Christey, Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">I think we can define appropriate, take a look at the nt security .pdf
and see if you can't see a way to phrase specific keys in a way that
defines inappropriate.</comment>
<comment voter="Christey">Upon further reflection, this is too high-level for CVE.
Specific registry keys with bad permissions is roughly
equivalent to Unix configuration files that have bad
permissions; those permission problems can be created by
any vendor, not just a specific one.  Therefore this
candidate should be RECAST into each separate registry
key that has this problem.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0590" seq="1999-0590">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A system does not present an appropriate legal message or warning to a user who is accessing it.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<modify count="1">Christey</modify>
<recast count="1">Shostack</recast>
</votes>
<comments>
<comment voter="Christey">ADDREF CIAC:J-043
URL:http://ciac.llnl.gov/ciac/bulletins/j-043.shtml
Also add &quot;banner&quot; to the description to facilitate search.</comment>
<comment voter="Baker">Should be in place where ever it is possible</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0591" seq="1999-0591">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>An event log in Windows NT has inappropriate access permissions.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">splain Lucy, splain</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0592" seq="1999-0592">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>The Logon box of a Windows NT system displays the name of the last user who logged in.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="2">Northcutt, Wall</reject>
</votes>
<comments>
<comment voter="Wall">Information gathering, not vulnerability</comment>
<comment voter="Northcutt">Ah a C2 weenie must have snuck this in, this can be a good thing 
not just vulnerability</comment>
<comment voter="Frech">XF:nt-display-last-username(1353)
Use it if you will. :-) If not, let us know so I can remove the CAN
reference from our database.</comment>
<comment voter="Christey">MSKB:Q114463
http://support.microsoft.com/support/kb/articles/q114/4/63.asp</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0593" seq="1999-0593">
<status>Candidate</status>
<phase date="20091029">Modified</phase>
<desc>The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.</desc>
<refs>
<ref source="MISC" url="http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true">http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true</ref>
<ref source="CONFIRM" url="http://technet.microsoft.com/en-us/library/cc722469.aspx">http://technet.microsoft.com/en-us/library/cc722469.aspx</ref>
<ref source="OSVDB" url="http://osvdb.org/59333">59333</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1291">nt-shutdown-without-logon(1291)</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Wall">Still a denial of service.</comment>
<comment voter="Northcutt">May well be appropriate</comment>
<comment voter="Frech">XF:nt-shutdown-without-logon(1291)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0594" seq="1999-0594">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Wall">Perhaps it can be re-worded to &quot;removable media drives
such as a floppy disk drive or CDROM drive can be accessed (shared) in a
Windows NT system.&quot;</comment>
<comment voter="Northcutt">- what good is my NT w/o its floppy</comment>
<comment voter="Frech">XF:nt-allocate-cdroms(1294)
XF:nt-allocate-floppy(1318)</comment>
<comment voter="Christey">MSKB:Q172520
URL:http://support.microsoft.com/support/kb/articles/q172/5/20.asp</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0595" seq="1999-0595">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.</desc>
<refs>
<ref source="MSKB">Q182086</ref>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Northcutt</noop>
</votes>
<comments>
<comment voter="Frech">XF:nt-clearpage(216)
XF:reg-pagefile-clearing(2551)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0596" seq="1999-0596">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A Windows NT log file has an inappropriate maximum size or retention period.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="2">Northcutt, Wall</reject>
</votes>
<comments>
<comment voter="Northcutt">define appropriate</comment>
<comment voter="Frech">XF:reg-app-log-small(2521)
XF:reg-sec-log-maxsize(2577)
XF:reg-sys-log-small(2586)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0597" seq="1999-0597">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Wall</reject>
</votes>
<comments>
<comment voter="Frech">XF:nt-forced-logoff(1343)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0598" seq="1999-0598">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.</desc>
<refs>
</refs>
<votes>
<accept count="3">Armstrong, Baker, Northcutt</accept>
<noop count="1">Frech</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Waiting for CIEL.</comment>
<comment voter="Christey">This is a design flaw, along with the other reported IDS
problems; at least reference Ptacek/Newsham's paper.</comment>
<comment voter="Christey">URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0599" seq="1999-0599">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<noop count="1">Frech</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Waiting for CIEL.</comment>
<comment voter="Christey">This is a design flaw, along with the other reported IDS
problems; at least reference Ptacek/Newsham's paper.</comment>
<comment voter="Christey">URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0600" seq="1999-0600">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A network intrusion detection system (IDS) does not verify the checksum on a packet.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<noop count="1">Frech</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Waiting for CIEL.</comment>
<comment voter="Christey">This is a design flaw, along with the other reported IDS
problems; at least reference Ptacek/Newsham's paper.</comment>
<comment voter="Christey">URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0601" seq="1999-0601">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<noop count="1">Frech</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Waiting for Godot, er, CIEL.</comment>
<comment voter="Christey">This is a design flaw, along with the other reported IDS
problems; at least reference Ptacek/Newsham's paper.</comment>
<comment voter="Christey">URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0602" seq="1999-0602">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>A network intrusion detection system (IDS) does not properly reassemble fragmented packets.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Northcutt</accept>
<noop count="1">Frech</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Waiting for CIEL.</comment>
<comment voter="Christey">This is a design flaw, along with the other reported IDS
problems; at least reference Ptacek/Newsham's paper.</comment>
<comment voter="Christey">URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0603" seq="1999-0603">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="2">Northcutt, Wall</reject>
</votes>
<comments>
<comment voter="Frech">XF:nt-system-operator
XF:nt-admin-group
XF:nt-replicator
XF:nt-print-operator
XF:nt-power-user
XF:nt-guest-in-group
XF:nt-backup-operator
XF:nt-domain-admin
XF:nt-domain-guest
XF:win2k-acct-oper-grp
XF:win2k-admin-grp
XF:win2k-backup-oper-grp
XF:win2k-certpublishers-grp
XF:win2k-dhcp-admin-grp
XF:win2k-dnsadm-grp
XF:win2k-domainadm-grp
XF:win2k-entadm-grp
XF:win2k-printoper-grp
XF:win2k-replicator-grp
XF:win2k-schemaadm-grp
XF:win2k-serveroper-grp
You asked for it... :-) Use or reject at your discretion. If rejected,
please let us know so we can remove CAN references from database.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0604" seq="1999-0604">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>An incorrect configuration of the WebStore 1.0 shopping cart CGI program &quot;web_store.cgi&quot; could disclose private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="2">Northcutt, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:webstore-misconfig(3861)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0605" seq="1999-0605">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>An incorrect configuration of the Order Form 1.0 shopping cart  CGI program could disclose private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Northcutt, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:orderform-misconfig(3860)</comment>
<comment voter="Christey">BID:2021</comment>
<comment voter="Christey">Mention affected files: order_log_v12.dat and order_log.dat
fix version number (1.2)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0606" seq="1999-0606">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>An incorrect configuration of the EZMall 2000 shopping cart  CGI program &quot;mall2000.cgi&quot; could disclose private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Northcutt, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:ezmall2000-misconfig(3859)</comment>
<comment voter="Christey">Add mall_log_files/order.log to desc</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0607" seq="1999-0607">
<status>Candidate</status>
<phase date="20060608">Modified</phase>
<desc>quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Northcutt, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:quikstore-misconfig(3858)</comment>
<comment voter="Christey">http://www.quikstore.com/help/pages/Security/security.htm says:

&quot;It is IMPORTANT that during the setup of the QuikStore program, you
check to make sure that the cgi-bin or executable program directory
of your web site not be viewable from the outside world. You don't
want the users to have access to your programs or log files that could
be stored there!

...

If you can view or download these files from the browser, someone
else can too&quot;

So is this a configuration problem?  See the configuration file at
http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm
The [DIRECTORY_PATHS] section identifies pathnames and describes how
pathnames are constructed.  It clearly uses relative pathnames,
so all data is underneath the base directory!!

If we call this a configuration problem, then maybe this (and
all other &quot;CGI-data-in-web-tree&quot; configuration problems) should
be combined.</comment>
<comment voter="Christey">Consider adding BID:1983</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0608" seq="1999-0608">
<status>Entry</status>
<desc>An incorrect configuration of the PDG Shopping Cart CGI program &quot;shopper.cgi&quot; could disclose private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
<ref source="CONFIRM" url="http://www.pdgsoft.com/Security/security.html.">http://www.pdgsoft.com/Security/security.html.</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3857">pdgsoftcart-misconfig(3857)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0609" seq="1999-0609">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>An incorrect configuration of the SoftCart CGI program &quot;SoftCart.exe&quot; could disclose private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Northcutt, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:softcart-misconfig(3856)</comment>
<comment voter="Christey">Consider adding BID:2055</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0610" seq="1999-0610">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>An incorrect configuration of the Webcart CGI program could disclose private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="2">Northcutt, Wall</noop>
</votes>
<comments>
<comment voter="Frech">Cite reference as:
BUGTRAQ:19990424  Re: Shopping Carts exposing CC data 
URL:
http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%
3D1%26date%3D2000-08-22%26msg%3D3720E2B6.6031A2E7@datashopper.dk</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:webcart-data-exposure(8374)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0611" seq="1999-0611">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>A system-critical Windows NT registry key has an inappropriate value.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="1">Baker</noop>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">I think we can define appropriate, take a look at the nt security .pdf
and see if you can't see a way to phrase specific keys in a way that
defines inappropriate.</comment>
<comment voter="Baker">too vague</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0612" seq="1999-0612">
<status>Entry</status>
<desc>A version of finger is running that exposes valid user information to any entity on the network.</desc>
<refs>
<ref source="XF">finger-out</ref>
<ref source="XF">finger-running</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0613" seq="1999-0613">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>The rpc.sprayd service is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Frech">XF:sprayd</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0614" seq="1999-0614">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The FTP service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0615" seq="1999-0615">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The SNMP service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Prosser, Wall</accept>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Baker">Although newer versions on snmp are not as vulnerable as prior versions,
this can still be a significant risk of exploitation, as seen in recent
attacks on snmp services via automated worms</comment>
<comment voter="Christey">XF:snmp(132) ?</comment>
<comment voter="Prosser">This fits the &quot;exposure&quot; description although we also know there are many vulnerabilities in SNMP.  This is more of a policy/best practice issue for administrators.  If you need SNMP lock it down as tight as you can, if you don't need it, don't run it.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0616" seq="1999-0616">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The TFTP service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0617" seq="1999-0617">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The SMTP service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0618" seq="1999-0618">
<status>Candidate</status>
<phase date="19990921">Modified</phase>
<desc>The rexec service is running.</desc>
<refs>
<ref source="XF">rexec</ref>
</refs>
<votes>
<accept count="4">Baker, Northcutt, Ozancin, Wall</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:decod-rexec
XF:rexec</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0619" seq="1999-0619">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The Telnet service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0620" seq="1999-0620">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A component service related to NIS is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Christey">XF:ypserv(261)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0621" seq="1999-0621">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A component service related to NETBIOS is running.&quot;</desc>
<refs>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1024">oval:org.mitre.oval:def:1024</ref>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<modify count="1">Frech</modify>
<reject count="2">LeBlanc, Northcutt</reject>
</votes>
<comments>
<comment voter="LeBlanc">There is insufficient description to even know what this is.
Lots of component services related to NetBIOS run, and usually do not
constitute a problem.</comment>
<comment voter="Frech">associated to:
XF:nt-alerter(29)
XF:nt-messenger(69)
XF:reg-ras-gateway-enabled(2567)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0622" seq="1999-0622">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A component service related to DNS service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0623" seq="1999-0623">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The X Windows service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Christey">Add &quot;X11&quot; to facilitate search.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0624" seq="1999-0624">
<status>Candidate</status>
<phase date="19990925">Interim</phase>
<desc>The rstat/rstatd service is running.</desc>
<refs>
<ref source="XF">rstat-out</ref>
<ref source="XF">rstatd</ref>
</refs>
<votes>
<accept count="3">Baker, Northcutt, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="2">Meunier, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:rstat-out
XF:rstatd</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0625" seq="1999-0625">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>The rpc.rquotad service is running.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Northcutt, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:rquotad</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0626" seq="1999-0626">
<status>Entry</status>
<desc>A version of rusers is running that exposes valid user information to any entity on the network.</desc>
<refs>
<ref source="XF">rusersd</ref>
<ref source="XF">ruser</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0627" seq="1999-0627">
<status>Entry</status>
<desc>The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.</desc>
<refs>
<ref source="XF">rexd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0628" seq="1999-0628">
<status>Entry</status>
<desc>The rwho/rwhod service is running, which exposes machine status and user information.</desc>
<refs>
<ref source="XF">rwhod</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0629" seq="1999-0629">
<status>Candidate</status>
<phase date="19990721">Proposed</phase>
<desc>The ident/identd service is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Frech">possibly XF:identd?</comment>
<comment voter="Christey">XF:ident-users(318) ?</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:identd-vuln(61)
XF:ident-users(318)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0630" seq="1999-0630">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The NT Alerter and Messenger services are running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Christey">http://support.microsoft.com/support/kb/articles/q189/2/71.asp</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0631" seq="1999-0631">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The NFS service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Christey">XF:nfs-nfsd(76) ?</comment>
<comment voter="Christey">Add rpc.mountd/mountd to facilitate search.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0632" seq="1999-0632">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The RPC portmapper service is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0633" seq="1999-0633">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The HTTP/WWW service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0634" seq="1999-0634">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The SSH service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0635" seq="1999-0635">
<status>Candidate</status>
<phase date="20060122">Modified</phase>
<desc>The echo service is running.</desc>
<refs>
<ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref>
<ref source="SECUNIA" url="http://secunia.com/advisories/18514">18514</ref>
</refs>
<votes>
<accept count="3">Baker, Northcutt, Wall</accept>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Northcutt">The method to my madness is echo is the common denom in the dos attack</comment>
<comment voter="Christey">How much of this is an overlap with the echo/chargen flood
problem (CVE-1999-0103)?  If this is only an exposure because
of CVE-1999-0103, then maybe this should be REJECTed.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0636" seq="1999-0636">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The discard service is running.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<noop count="1">Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0637" seq="1999-0637">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The systat service is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0638" seq="1999-0638">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The daytime service is running.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<noop count="1">Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0639" seq="1999-0639">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The chargen service is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">How much of this is an overlap with the echo/chargen flood
problem (CVE-1999-0103)?  If this is only an exposure because
of CVE-1999-0103, then maybe this should be REJECTed.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0640" seq="1999-0640">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The Gopher service is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0641" seq="1999-0641">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The UUCP service is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0642" seq="1999-0642">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A POP service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0643" seq="1999-0643">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The IMAP service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0644" seq="1999-0644">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The NNTP news service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Christey">XF:nntp-post(88) ?</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0645" seq="1999-0645">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The IRC service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Christey">XF:irc-server(767) ?</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0646" seq="1999-0646">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The LDAP service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0647" seq="1999-0647">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The bootparam (bootparamd) service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Frech">XF:bootp</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0648" seq="1999-0648">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The X25 service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0649" seq="1999-0649">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The FSP service is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<noop count="1">Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0650" seq="1999-0650">
<status>Candidate</status>
<phase date="20060608">Modified</phase>
<desc>The netstat service is running, which provides sensitive information to remote attackers.</desc>
<refs>
<ref source="XF">netstat(72)</ref>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0651" seq="1999-0651">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>The rsh/rlogin service is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Christey">aka &quot;shell&quot; on UNIX systems (at least Solaris) in the
/etc/inetd.conf file.</comment>
<comment voter="Frech">associated to:
XF:nt-rlogin(92) 
XF:rsh-svc(114)
XF:rshd(2995)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0652" seq="1999-0652">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A database service is running, e.g. a SQL server, Oracle, or mySQL.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Frech">XF:nt-sql-server(1289)
XF:msql-detect(2211)
XF:oracle-detect(2388)
XF:sybase-detect-namedpipes(1461)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0653" seq="1999-0653">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>A component service related to NIS+ is running.</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0654" seq="1999-0654">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>The OS/2 or POSIX subsystem in NT is enabled.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Wall">These subsystems could still allow a process to persist across logins.</comment>
<comment voter="Frech">XF:nt-posix(217)
XF:nt-posix-sub-c2(2397)
XF:nt-posix-sub-onceonly(2478)
XF:nt-os2-sub(218)
XF:nt-os2-sub-c2(2396)
XF:nt-os2-sub-onceonly(2477)
XF:nt-os2-registry(2550)</comment>
<comment voter="Christey">s2-file-os2(1865)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0655" seq="1999-0655">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE.  Notes: the former description is: &quot;A service may include useful information in its banner or help function (such as the name and version), making it useful for information gathering activities.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="5">Baker, Frech, Northcutt, Ozancin, Wall</accept>
</votes>
<comments>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to ACCEPT]</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0656" seq="1999-0656">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.</desc>
<refs>
<ref source="MISC" url="http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638">http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/348">linux-ugidd(348)</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<noop count="1">Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0657" seq="1999-0657">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>WinGate is being used.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<noop count="1">Wall</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0658" seq="1999-0658">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;DCOM is running.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="2">Baker, Wall</accept>
<reject count="1">Northcutt</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0659" seq="1999-0659">
<status>Candidate</status>
<phase date="20080731">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present.&quot;</desc>
<refs>
</refs>
<votes>
<reject count="3">Baker, Northcutt, Wall</reject>
</votes>
<comments>
<comment voter="Wall">Don't consider this a service or a problem.</comment>
<comment voter="Baker">concur with wall on this</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0660" seq="1999-0660">
<status>Candidate</status>
<phase date="20080730">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE.  It might be more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A hacker utility, back door, or Trojan Horse is installed on a system, e.g. NetBus, Back Orifice, Rootkit, etc.&quot;</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Hill, Northcutt, Wall</accept>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Christey">Add &quot;back door&quot; to description.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0661" seq="1999-0661">
<status>Candidate</status>
<phase date="20050529">Modified</phase>
<desc>A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1994-07.html">CA-1994-07</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1994-14.html">CA-1994-14</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1999-01.html">CA-1999-01</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1999-02.html">CA-1999-02</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2002-28.html">CA-2002-28</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102820843403741&amp;w=2">20020801 trojan horse in recent openssh (version 3.4 portable 1)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102821663814127&amp;w=2">20020801 OpenSSH Security Advisory:  Trojaned Distribution Files</ref>
<ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/294539">20021009 Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/5921">5921</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/10313.php">sendmail-backdoor(10313)</ref>
</refs>
<votes>
<accept count="4">Baker, Hill, Northcutt, Wall</accept>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">Should add the specific CERT advisory references for
well-known Trojaned software.</comment>
<comment voter="TCP Wrappers -">CERT:CA-1999-01
CERT:CA-1999-02 includes util-linux
wuarchive - CERT:CA-94.07
IRC client - CERT:CA-1994-14</comment>
<comment voter="Christey">BUGTRAQ:20020801 trojan horse in recent openssh (version 3.4 portable 1)
Modify description to use dot notation.</comment>
<comment voter="Christey">CERT:CA-2002-24
URL:http://www.cert.org/advisories/CA-2002-24.html
XF:openssh-backdoor(9763)
URL:http://www.iss.net/security_center/static/9763.php
BID:5374
URL:http://www.securityfocus.com/bid/5374</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="Christey">Add libpcap and tcpdump:
BUGTRAQ:20021113 Latest libpcap &amp; tcpdump sources from tcpdump.org contain a trojan
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=103722456708471&amp;w=2
CERT:CA-2002-30
URL:http://www.cert.org/advisories/CA-2002-30.html

This CAN has been active for over 4 years.  At this moment, my
thinking is that we should SPLIT this CAN into each separate
trojaned product, then create some criteria that restrict
creation of new CANs to &quot;widespread&quot; or &quot;important&quot; products only.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0662" seq="1999-0662">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.</desc>
<refs>
</refs>
<votes>
<accept count="4">Baker, Hill, Northcutt, Wall</accept>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-0663" seq="1999-0663">
<status>Candidate</status>
<phase date="19990804">Proposed</phase>
<desc>A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.</desc>
<refs>
</refs>
<votes>
<accept count="3">Baker, Hill, Wall</accept>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">This needs to be worded carefully.  
1. Rootkits evade checksum detection.
2. The modification could be positive (a patch)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0664" seq="1999-0664">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>An application-critical Windows NT registry key has inappropriate permissions.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="1">Baker</noop>
<recast count="2">Christey, Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">I think we can define appropriate, take a look at the nt security .pdf
and see if you can't see a way to phrase specific keys in a way that
defines inappropriate.</comment>
<comment voter="Christey">Upon further reflection, this is too high-level for CVE.
Specific registry keys with bad permissions is roughly
equivalent to Unix configuration files that have bad
permissions; those permission problems can be created by
any vendor, not just a specific one.  Therefore this
candidate should be RECAST into each separate registry
key that has this problem.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0665" seq="1999-0665">
<status>Candidate</status>
<phase date="19990803">Proposed</phase>
<desc>An application-critical Windows NT registry key has an inappropriate value.</desc>
<refs>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="1">Baker</noop>
<recast count="1">Northcutt</recast>
</votes>
<comments>
<comment voter="Northcutt">I think we can define appropriate, take a look at the nt security .pdf
and see if you can't see a way to phrase specific keys in a way that
defines inappropriate.</comment>
<comment voter="Baker">very vague</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0667" seq="1999-0667">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.</desc>
<refs>
</refs>
<votes>
<accept count="2">Blake, Cole</accept>
<modify count="1">Stracener</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Frech</reject>
</votes>
<comments>
<comment voter="Stracener">Add Ref: BUGTRAQ:19970919 Playing redir games with ARP and ICMP</comment>
<comment voter="Frech">Cannot proceed without a reference. Too vague, and resembles XF:netbsd-arp:
CVE-1999-0763: NetBSD on a multi-homed host allows ARP packets on one
network to modify ARP entries on another connected network.
CVE-1999-0764: NetBSD allows ARP packets to overwrite static ARP entries.
Will reconsider if reference provides enough information to render a
distinction.</comment>
<comment voter="Christey">This particular vulnerability was exploited by an attacker
during the ID'Net IDS test network exercise at the SANS
Network Security '99 conference.  The attacker adapted a
publicly available program that was able to spoof another
machine on the same physical network.

See http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019797&amp;w=2
for the Bugtraq reference that Tom Stracener suggested.
This generated a long thread on Bugtraq in 1997.</comment>
<comment voter="Blake">I'll second Tom's request to add the reference, it's a very
posting good and the vulnerability is clearly derivative of
the work.

(I do recall talking to the guy and drafting a description.)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0668" seq="1999-0668">
<status>Entry</status>
<desc>The scriptlet.typelib ActiveX control is marked as &quot;safe for scripting&quot; for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</desc>
<refs>
<ref source="BUGTRAQ">19990821 IE 5.0 allows executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp">MS99-032</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/598">598</ref>
<ref source="XF">ms-scriptlet-eyedog-unsafe</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240308">Q240308</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0669" seq="1999-0669">
<status>Candidate</status>
<phase date="19991229">Interim</phase>
<desc>The Eyedog ActiveX control is marked as &quot;safe for scripting&quot; for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</desc>
<refs>
<ref source="MS">MS99-032</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref>
<ref source="XF">ms-scriptlet-eyedog-unsafe</ref>
<ref source="MSKB">Q240308</ref>
</refs>
<votes>
<accept count="5">Baker, Cole, Ozancin, Prosser, Wall</accept>
<modify count="2">Frech, Stracener</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:ms-scriptlet-eyedog-unsafe</comment>
<comment voter="Stracener">Add Ref: MSKB Q240308</comment>
<comment voter="Christey">Should CVE-1999-0669 and 668 be merged?  If not, then this is
a reason for not merging CVE-1999-0988 and CVE-1999-0828.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0670" seq="1999-0670">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp">MS99-032</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref>
</refs>
<votes>
<accept count="3">Ozancin, Prosser, Wall</accept>
<modify count="2">Frech, Stracener</modify>
<reject count="2">Baker, Cole</reject>
</votes>
<comments>
<comment voter="Frech">XF:ie-eyedog-bo</comment>
<comment voter="Cole">Based on the references and information listed this is the same as
CVE-1999-0669</comment>
<comment voter="Stracener">Add Ref: MSKB Q240308</comment>
<comment voter="Baker">Duplicate</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0671" seq="1999-0671">
<status>Entry</status>
<desc>Buffer overflow in ToxSoft NextFTP client through CWD command.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/572">572</ref>
<ref source="XF">toxsoft-nextftp-cwd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0672" seq="1999-0672">
<status>Entry</status>
<desc>Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.</desc>
<refs>
<ref source="XF">fujitsu-topic-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/573">573</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0673" seq="1999-0673">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Buffer overflow in ALMail32 POP3 client via From: or To: headers.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/574">574</ref>
</refs>
<votes>
<accept count="6">Baker, Blake, Cole, Collins, Levy, Wall</accept>
<modify count="2">Frech, Stracener</modify>
<noop count="3">Armstrong, Landfield, Oliver</noop>
<reviewing count="1">Ozancin</reviewing>
</votes>
<comments>
<comment voter="Stracener">AddRef: ShadowPenguinSecurity:PenguinToolbox,No.037</comment>
<comment voter="Frech">XF:almail-bo</comment>
<comment voter="CHANGE">[Cole changed vote from NOOP to ACCEPT]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0674" seq="1999-0674">
<status>Entry</status>
<desc>The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.</desc>
<refs>
<ref source="NETBSD">1999-011</ref>
<ref source="OPENBSD">Aug 9,1999</ref>
<ref source="FREEBSD">FreeBSD-SA-99:02</ref>
<ref source="BUGTRAQ">19990809 profil(2) bug, a simple test program</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/570">570</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-067.shtml">J-067</ref>
<ref source="XF">netbsd-profil</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0675" seq="1999-0675">
<status>Entry</status>
<desc>Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/23615">19990809 FW1 UDP Port 0 DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/576">576</ref>
<ref source="XF">checkpoint-port</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1038">1038</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0676" seq="1999-0676">
<status>Entry</status>
<desc>sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19990809134220.A1191@hades.chaoz.org">19990808 sdtcm_convert</ref>
<ref source="XF">sun-sdtcm-convert</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/575">575</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0677" seq="1999-0677">
<status>Candidate</status>
<phase date="19991228">Modified</phase>
<desc>The WebRamp web administration utility has a default password.</desc>
<refs>
<ref source="BUGTRAQ">19990802 [LoWNOISE] Password hunting with webramp</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/577">577</ref>
</refs>
<votes>
<accept count="3">Baker, Blake, Stracener</accept>
<modify count="2">Cole, Frech</modify>
<noop count="2">Armstrong, Christey</noop>
</votes>
<comments>
<comment voter="Cole">I would add that is is not forced to be changed.</comment>
<comment voter="Frech">XF:webramp-default-password</comment>
<comment voter="Christey">This problem may have been detected in January 1999:
BUGTRAQ:19990121 Re: WebRamp M3 remote network access bug
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91702375402055&amp;w=2</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0678" seq="1999-0678">
<status>Entry</status>
<desc>A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.</desc>
<refs>
<ref source="XF">apache-debian-usrdoc</ref>
<ref source="BUGTRAQ">19990405 An issue with Apache on Debian</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/318">318</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0679" seq="1999-0679">
<status>Entry</status>
<desc>Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.</desc>
<refs>
<ref source="BUGTRAQ">19990813 w00w00's efnet ircd advisory (exploit included)</ref>
<ref source="CONFIRM" url="http://www.efnet.org/archive/servers/hybrid/ChangeLog">http://www.efnet.org/archive/servers/hybrid/ChangeLog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/581">581</ref>
<ref source="XF">hybrid-ircd-minvite-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0680" seq="1999-0680">
<status>Entry</status>
<desc>Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-028.mspx">MS99-028</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238600">Q238600</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-057.shtml">J-057</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/571">571</ref>
<ref source="XF">nt-terminal-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0681" seq="1999-0681">
<status>Entry</status>
<desc>Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1999-q3/0381.html">19990807 Crash FrontPage Remotely...</ref>
<ref source="XF" url="http://xforce.iss.net/static/3117.php">frontpage-pws-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/568">568</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0682" seq="1999-0682">
<status>Entry</status>
<desc>Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-027.mspx">MS99-027</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237927">Q237927</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/567">567</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-056.shtml">J-056</ref>
<ref source="XF">exchange-relay</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0683" seq="1999-0683">
<status>Entry</status>
<desc>Denial of service in Gauntlet Firewall via a malformed ICMP packet.</desc>
<refs>
<ref source="XF">gauntlet-dos</ref>
<ref source="BUGTRAQ">19990729 Remotely Lock Up Gauntlet 5.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/556">556</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1029">1029</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0684" seq="1999-0684">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>Denial of service in Sendmail 8.8.6 in HPUX.</desc>
<refs>
<ref source="HP">HPSBUX9904-097</ref>
</refs>
<votes>
<accept count="2">Blake, Cole</accept>
<modify count="3">Frech, Prosser, Stracener</modify>
<noop count="1">Baker</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Stracener">Add Ref: CIAC: J-040</comment>
<comment voter="Prosser">Might change description to indicate DoS caused by multiple connections</comment>
<comment voter="Christey">Andre's right.  This is a duplicate of CVE-1999-0684.</comment>
<comment voter="Frech">Without further information and/or references, this issue looks like an
ambiguous version of CVE-1999-0478: Denial of service in HP-UX sendmail
8.8.6 related to accepting connections.

(was REJECT)
XF:hp-sendmail-connect-dos</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0685" seq="1999-0685">
<status>Entry</status>
<desc>Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Netscape communicator 4.06J, 4.5J-4.6J, 4.61e Buffer Overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/618">618</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0686" seq="1999-0686">
<status>Entry</status>
<desc>Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.</desc>
<refs>
<ref source="BUGTRAQ">19990514 TGAD DoS</ref>
<ref source="BUGTRAQ">19990610 Re: VVOS/Netscape Bug</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-098">HPSBUX9906-098</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-046.shtml">J-046</ref>
<ref source="XF">hp-tgad-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0687" seq="1999-0687">
<status>Entry</status>
<desc>The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in ttsession</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="COMPAQ">SSRT0617U_TTSESSION</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-001.shtml">K-001</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/637">637</ref>
<ref source="XF">cde-ttsession-rpc-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0688" seq="1999-0688">
<status>Entry</status>
<desc>Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-101">HPSBUX9907-101</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/545">545</ref>
<ref source="XF">hp-sd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0689" seq="1999-0689">
<status>Entry</status>
<desc>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in dtspcd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1880">oval:org.mitre.oval:def:1880</ref>
<ref source="XF">cde-dtspcd-file-auth</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/636">636</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0690" seq="1999-0690">
<status>Entry</status>
<desc>HP CDE program includes the current directory in root's PATH variable.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-100">HPSBUX9907-100</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-053.shtml">J-053</ref>
<ref source="XF">hp-cde-directory</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0691" seq="1999-0691">
<status>Entry</status>
<desc>Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in dtaction</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="COMPAQ">SSRTO615U_DTACTION</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/635">635</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3078">oval:org.mitre.oval:def:3078</ref>
<ref source="XF">cde-dtaction-username-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0692" seq="1999-0692">
<status>Entry</status>
<desc>The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-99-09</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-052.shtml">J-052</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990701-01-P">19990701-01-P</ref>
<ref source="XF">sgi-arrayd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0693" seq="1999-0693">
<status>Entry</status>
<desc>Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-99-11</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/641">641</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4374">oval:org.mitre.oval:def:4374</ref>
<ref source="XF">cde-dtsession-env-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0694" seq="1999-0694">
<status>Entry</status>
<desc>Denial of service in AIX ptrace system call allows local users to crash the system.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-055.shtml">J-055</ref>
<ref source="IBM">ERS-SVA-E01-1999:002.1</ref>
<ref source="XF">aix-ptrace-halt</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0695" seq="1999-0695">
<status>Entry</status>
<desc>The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19990904 [Sybase] software vendors do not think about old bugs</ref>
<ref source="XF">http-powerdynamo-dotdotslash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/620">620</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1064">1064</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0696" seq="1999-0696">
<status>Entry</status>
<desc>Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).</desc>
<refs>
<ref source="BUGTRAQ">19990709 Exploit of rpc.cmsd</ref>
<ref source="SCO">SB-99.12</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/188">00188</ref>
<ref source="SUNBUG">4230754</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9908-102">HPSBUX9908-102</ref>
<ref source="COMPAQ">SSRT0614U_RPC_CMSD</ref>
<ref source="CERT">CA-99-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-051.shtml">J-051</ref>
<ref source="XF">sun-cmsd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0697" seq="1999-0697">
<status>Entry</status>
<desc>SCO Doctor allows local users to gain root privileges through a Tools option.</desc>
<refs>
<ref source="BUGTRAQ">19990908 SCO 5.0.5 /bin/doctor nightmare</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/621">621</ref>
<ref source="XF">sco-doctor-execute</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0698" seq="1999-0698">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.</desc>
<refs>
</refs>
<votes>
<accept count="6">Armstrong, Baker, Blake, Cole, Collins, Ozancin</accept>
<modify count="1">Frech</modify>
<noop count="4">Landfield, Levy, Stracener, Wall</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Stracener">Is the candidate referring to the denial of service problem mentioned in
the
changelogs for versions previous to 1.4.3-1 or does it pertain to some
problem with or
1.4.8-1?</comment>
<comment voter="Frech">Depending on the version, this could be any number of DoSes 
related to ippl.
From http://www.larve.net/ippl/:
9 April 1999: version 1.4.3 released, correctly fixing a 
potential denial of service attack.
7 April 1999: version 1.4.2 released, fixing a potential 
denial of service attack. 
XF:linux-ippl-dos</comment>
<comment voter="Christey">Changelog: http://pltplp.net/ippl/docs/HISTORY

See comments for version 1.4.2 and 1.4.3
Another source: http://freshmeat.net/news/1999/04/08/923586598.html</comment>
<comment voter="CHANGE">[Stracener changed vote from REVIEWING to NOOP]</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REJECT]</comment>
<comment voter="Christey">As mentioned by others, this could apply to several different
versions.  Since the description is too vague, this CAN should
be REJECTED and recast into other candidates.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0699" seq="1999-0699">
<status>Entry</status>
<desc>The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.</desc>
<refs>
<ref source="BUGTRAQ">19990908 [Security] Spoofed Id in Bluestone Sapphire/Web</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/623">623</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0700" seq="1999-0700">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237185">Q237185</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-026.mspx">MS99-026</ref>
<ref source="XF">nt-malformed-dialer</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0701" seq="1999-0701">
<status>Entry</status>
<desc>After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-036.mspx">MS99-036</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q173039">Q173039</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/626">626</ref>
<ref source="XF">nt-install-unattend-file</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0702" seq="1999-0702">
<status>Entry</status>
<desc>Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the &quot;ImportExportFavorites&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ">19990909 IE 5.0 security vulnerabilities - ImportExportFavorites - at least creating and overwriting files, probably executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-037.mspx">MS99-037</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241361">Q241361</ref>
<ref source="XF">ie5-import-export-favorites</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/627">627</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0703" seq="1999-0703">
<status>Entry</status>
<desc>OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.</desc>
<refs>
<ref source="BUGTRAQ">19990805 4.4 BSD issue -- chflags</ref>
<ref source="OPENBSD">Jul30,1999</ref>
<ref source="FREEBSD">FreeBSD-SA-99:01</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-066.shtml">J-066</ref>
<ref source="XF">openbsd-chflags-fchflags-permitted</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0704" seq="1999-0704">
<status>Entry</status>
<desc>Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.</desc>
<refs>
<ref source="REDHAT">RHSA-1999:032-01</ref>
<ref source="CALDERA">CSSA-1999:024.0</ref>
<ref source="FREEBSD">SA-99:06</ref>
<ref source="DEBIAN">19991018</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/614">614</ref>
<ref source="CERT">CA-99-12</ref>
<ref source="XF">amd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0705" seq="1999-0705">
<status>Entry</status>
<desc>Buffer overflow in INN inews program.</desc>
<refs>
<ref source="XF">inn-inews-bo</ref>
<ref source="REDHAT">RHSA1999033_01</ref>
<ref source="CALDERA">CSSA-1999-026</ref>
<ref source="SUSE">19990831 Security hole in INN</ref>
<ref source="DEBIAN">19990907</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/616">616</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0706" seq="1999-0706">
<status>Entry</status>
<desc>Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.</desc>
<refs>
<ref source="DEBIAN">19990807</ref>
<ref source="SUSE">19990817 Security hole in i4l (xmonisdn)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/583">583</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0707" seq="1999-0707">
<status>Entry</status>
<desc>The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-099">HPSBUX9906-099</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-050.shtml">J-050</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/493">493</ref>
<ref source="XF">hp-visualize-conference-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0708" seq="1999-0708">
<status>Entry</status>
<desc>Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.</desc>
<refs>
<ref source="BUGTRAQ">19990921 BP9909-00: cfingerd local buffer overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/651">651</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0710" seq="1999-0710">
<status>Entry</status>
<desc>The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.</desc>
<refs>
<ref source="BUGTRAQ">19990725 Redhat 6.0 cachemgr.cgi lameness</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid">http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-576">DSA-576</ref>
<ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref>
<ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-025.html">RHSA-1999:025</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-489.html">RHSA-2005:489</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2059">2059</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2385">http-cgi-cachemgr(2385)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0711" seq="1999-0711">
<status>Entry</status>
<desc>The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?t=92550157100002&amp;w=2&amp;r=1">19990430 *Huge* security hole in Oracle 8.0.5 with Intellegent agent installed</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92609807906778&amp;w=2">19990506 Oracle Security Followup, patch and FAQ: setuid on oratclsh</ref>
<ref source="XF">oracle-oratclsh</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0712" seq="1999-0712">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.</desc>
<refs>
<ref source="CALDERA">CSSA-1999:009</ref>
<ref source="XF">linux-coas</ref>
</refs>
<votes>
<accept count="4">Baker, Cole, Frech, Stracener</accept>
<modify count="1">Blake</modify>
<noop count="1">Armstrong</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Blake">This obscurely-written advisory seems to state that COAS will make the
file world-readable, not that it allows the user to make it so.  I hardly
think that allowing the user to turn off security is a vulnerability.</comment>
<comment voter="Christey">It's difficult to write the description based on what's in
the advisory.  If COAS inadvertently changes permissions
without user confirmation, then it should be ACCEPTed with
appropriate modification to the description.</comment>
<comment voter="Christey">ADDREF BID:137</comment>
<comment voter="CHANGE">[Armstrong changed vote from REVIEWING to NOOP]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0713" seq="1999-0713">
<status>Entry</status>
<desc>The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">19990404 Digital Unix 4.0E /var permission</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-044.shtml">J-044</ref>
<ref source="XF">cde-dtlogin</ref>
<ref source="COMPAQ">SSRT0600U</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0714" seq="1999-0714">
<status>Entry</status>
<desc>Vulnerability in Compaq Tru64 UNIX edauth command.</desc>
<refs>
<ref source="COMPAQ">SSRT0588U</ref>
<ref source="XF">du-edauth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0715" seq="1999-0715">
<status>Entry</status>
<desc>Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.</desc>
<refs>
<ref source="BUGTRAQ">19990519 Buffer Overruns in RAS allows execution of arbitary code as system</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-016.mspx">MS99-016</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230677">Q230677</ref>
<ref source="XF">nt-ras-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0716" seq="1999-0716">
<status>Entry</status>
<desc>Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.</desc>
<refs>
<ref source="XF">nt-helpfile-bo</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231605">Q231605</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp">MS99-015</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0717" seq="1999-0717">
<status>Entry</status>
<desc>A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-014.mspx">MS99-014</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231304">Q231304</ref>
<ref source="XF">excel-virus-warning</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0718" seq="1999-0718">
<status>Entry</status>
<desc>IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9908&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5534">19990823 IBM Gina security warning</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/608">608</ref>
<ref source="XF" url="http://xforce.iss.net/static/3166.php">ibm-gina-group-add</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0719" seq="1999-0719">
<status>Entry</status>
<desc>The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.</desc>
<refs>
<ref source="BUGTRAQ">19990802 Gnumeric potential security hole.</ref>
<ref source="REDHAT">RHSA-1999:023-01</ref>
<ref source="XF">gnu-guile-plugin-export</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/563">563</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0720" seq="1999-0720">
<status>Entry</status>
<desc>The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=lcamtuf.4.05.9907041223290.355-300000@nimue.ids.pl">19990823 [Linux] glibc 2.1.x / wu-ftpd &lt;=2.5 / BeroFTPD / lynx / vlock / mc / glibc 2.0.x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/597">597</ref>
<ref source="XF">linux-pt-chown</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0721" seq="1999-0721">
<status>Entry</status>
<desc>Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.</desc>
<refs>
<ref source="BINDVIEW">Phantom Technical Advisory</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231457">Q231457</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-020.mspx">MS99-020</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref>
<ref source="XF">msrpc-lsa-lookupnames-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0722" seq="1999-0722">
<status>Entry</status>
<desc>The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.</desc>
<refs>
<ref source="CERT">CA-99-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/558">558</ref>
<ref source="XF">cobalt-raq2-default-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0723" seq="1999-0723">
<status>Entry</status>
<desc>The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.</desc>
<refs>
<ref source="NTBUGTRAQ">19990411 Death by MessageBox</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-021.mspx">MS99-021</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233323">Q233323</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/478">478</ref>
<ref source="XF">nt-csrss-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0724" seq="1999-0724">
<status>Entry</status>
<desc>Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.</desc>
<refs>
<ref source="OPENBSD">Aug12,1999</ref>
<ref source="XF">openbsd-uio_offset-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6128">6128</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0725" seq="1999-0725">
<status>Entry</status>
<desc>When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. &quot;Double Byte Code Page&quot;.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233335">Q233335</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-022.mspx">MS99-022</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/477">477</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2302">iis-double-byte-code-page(2302)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0726" seq="1999-0726">
<status>Entry</status>
<desc>An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-023.mspx">MS99-023</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234557">Q234557</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/499">499</ref>
<ref source="XF">nt-malformed-image-header</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0727" seq="1999-0727">
<status>Entry</status>
<desc>A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.</desc>
<refs>
<ref source="OPENBSD">19990608 Packets that should have been handled by IPsec may be transmitted as cleartext</ref>
<ref source="XF">openbsd-ipsec-cleartext</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6127">6127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0728" seq="1999-0728">
<status>Entry</status>
<desc>A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-024.mspx">MS99-024</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q236359">Q236359</ref>
<ref source="XF">nt-ioctl-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0729" seq="1999-0729">
<status>Entry</status>
<desc>Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise34.php">19990823 Denial of Service Attack against Lotus Notes Domino Server 4.6</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-061.shtml">J-061</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/601">601</ref>
<ref source="XF">lotus-ldap-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1057">1057</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0730" seq="1999-0730">
<status>Entry</status>
<desc>The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.</desc>
<refs>
<ref source="DEBIAN">19990612</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0731" seq="1999-0731">
<status>Entry</status>
<desc>The KDE klock program allows local users to unlock a session using malformed input.</desc>
<refs>
<ref source="BUGTRAQ">19990623 Security flaw in klock</ref>
<ref source="CALDERA">CSSA-1999:017</ref>
<ref source="SUSE">19990629 Security hole in Klock</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/489">489</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0732" seq="1999-0732">
<status>Entry</status>
<desc>The logging facilitity of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.</desc>
<refs>
<ref source="DEBIAN">19990823b</ref>
<ref source="XF">smtp-refuser-tmp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0733" seq="1999-0733">
<status>Entry</status>
<desc>Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990626 VMWare Advisory - buffer overflows</ref>
<ref source="BUGTRAQ">19990626 VMware Security Alert</ref>
<ref source="BUGTRAQ">19990705 Re: VMWare Advisory.. - exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/490">490</ref>
<ref source="XF">vmware-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0734" seq="1999-0734">
<status>Entry</status>
<desc>A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.</desc>
<refs>
<ref source="CISCO"> CiscoSecure Access Control Server for UNIX Remote Administration Vulnerability</ref>
<ref source="XF">ciscosecure-read-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0735" seq="1999-0735">
<status>Entry</status>
<desc>KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.</desc>
<refs>
<ref source="ISS">KDE K-Mail File Creation Vulnerability</ref>
<ref source="CALDERA">CSSA-1999:016</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA1999015_01.html">RHSA-1999:015-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/300">300</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0736" seq="1999-0736">
<status>Candidate</status>
<phase date="20061101">Modified</phase>
<desc>The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="L0PHT">May7,1999</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref>
<ref source="MSKB">Q232449</ref>
<ref source="MSKB">Q231368</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:932">oval:org.mitre.oval:def:932</ref>
</refs>
<votes>
<accept count="4">Ozancin, Prosser, Stracener, Wall</accept>
<modify count="2">Cole, Frech</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:iis-samples-showcode</comment>
<comment voter="Cole">There are several sample files that allow this.  I would quote
showcode.asp but make it more generic.</comment>
<comment voter="Prosser">(Modify)
Have a question on this and on the following three candidates as well.  All
of these are part of the file viewers utilities that allow unauthorized
files reading, but MSKB Q231368 also mentioned the diagnostics
program,Winmsdp.exe, as another vulnerable viewer in this same set of
viewers.  If we are going to split out the seperate viewer tools then
shouldn't there should be a seperate CAN for Winmsdp.exe also.</comment>
<comment voter="Christey">Mike's question basically touches on the CD:SF-EXEC
content decision - what do you do when you have the same bug
in multiple executables?  CD:SF-EXEC needs to be reviewed
and approved by the Editorial Board before we can decide
what to do with this candidate.</comment>
<comment voter="Christey">Mark Burnett says that Microsoft's mention of winmsdp.exe in
MSKB:Q231368 may be an error, and that winmsdp.exe is a
Microsoft Diagnostics Report Generator which may not even
be installed as part of IIS.

Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html</comment>
<comment voter="Christey">ADDREF BID:167
URL:http://www.securityfocus.com/vdb/bottom.html?vid=167</comment>
<comment voter="Christey">MISC:http://p.ulh.as/xploitsdb/NT/iis38.html covers a showcode.asp
directory traversal vulnerability and refers to the L0pht advisory.

Mark Burnett's article is at:
MISC:http://www.securityfocus.com/infocus/1317</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0737" seq="1999-0737">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref>
<ref source="MSKB">Q231656</ref>
</refs>
<votes>
<accept count="4">Ozancin, Prosser, Stracener, Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Cole</reject>
</votes>
<comments>
<comment voter="Frech">XF:iis-samples-viewcode</comment>
<comment voter="Cole">I would combine this with the previous.</comment>
<comment voter="Prosser">(modify)
See comments in 0736 above</comment>
<comment voter="Christey">See http://www.securityfocus.com/focus/microsoft/iis/showcode.html
for additional details.</comment>
<comment voter="Christey">Mark Burnett's article is at:
MISC:http://www.securityfocus.com/infocus/1317</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0738" seq="1999-0738">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref>
<ref source="MSKB">Q232449</ref>
<ref source="MSKB">Q231368</ref>
</refs>
<votes>
<accept count="4">Ozancin, Prosser, Stracener, Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Cole</reject>
</votes>
<comments>
<comment voter="Frech">XF:iis-samples-code</comment>
<comment voter="Cole">Same as above</comment>
<comment voter="Prosser">(modify)
See comments in 0736 above</comment>
<comment voter="Christey">See http://www.securityfocus.com/focus/microsoft/iis/showcode.html
for additional details.</comment>
<comment voter="Christey">Mark Burnett's article is at:
MISC:http://www.securityfocus.com/infocus/1317</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0739" seq="1999-0739">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref>
<ref source="MSKB">Q232449</ref>
<ref source="MSKB">Q231368</ref>
</refs>
<votes>
<accept count="4">Ozancin, Prosser, Stracener, Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Cole</reject>
</votes>
<comments>
<comment voter="Frech">XF:iis-samples-codebrws</comment>
<comment voter="Cole">Same as above.</comment>
<comment voter="Prosser">(modify)
See comments in 0736 above</comment>
<comment voter="Christey">codebrw2.asp and Codebrw1.asp also need to be included
somewhere.

Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html</comment>
<comment voter="Christey">Mark Burnett's article is at:
MISC:http://www.securityfocus.com/infocus/1317</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0740" seq="1999-0740">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/594">594</ref>
<ref source="XF">linux-telnetd-term</ref>
<ref source="CALDERA">CSSA-1999:022</ref>
<ref source="REDHAT">RHSA1999029_01</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0741" seq="1999-0741">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.</desc>
<refs>
<ref source="BUGTRAQ">19990818 QMS 2060 printer security hole</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/593">593</ref>
<ref source="XF">qms-2060-no-root-password</ref>
</refs>
<votes>
<accept count="4">Baker, Frech, Levy, Stracener</accept>
<noop count="2">Christey, Oliver</noop>
</votes>
<comments>
<comment voter="Christey">change description - anyone can log on *as* root</comment>
<comment voter="Frech">(Note: this XF also cataloged under CVE-1999-0508.)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0742" seq="1999-0742">
<status>Entry</status>
<desc>The Debian mailman package uses weak authentication, which allows attackers to gain privileges.</desc>
<refs>
<ref source="DEBIAN">19990623</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/480">480</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0743" seq="1999-0743">
<status>Entry</status>
<desc>Trn allows local users to overwrite other users' files via symlinks.</desc>
<refs>
<ref source="BUGTRAQ">19990819 Insecure use of file in /tmp by trn</ref>
<ref source="DEBIAN">19990823c</ref>
<ref source="SUSE">19990824 Security hole in trn</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3144">trn-symlinks(3144)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0744" seq="1999-0744">
<status>Entry</status>
<desc>Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.</desc>
<refs>
<ref source="ISS">Buffer Overflow in Netscape Enterprise and FastTrack Web Servers</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/603">603</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0745" seq="1999-0745">
<status>Entry</status>
<desc>Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.</desc>
<refs>
<ref source="IBM">ERS-SVA-E01-1999:003.1</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-059.shtml">J-059</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/590">590</ref>
<ref source="XF">aix-pdnsd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0746" seq="1999-0746">
<status>Entry</status>
<desc>A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19990814 DOS against SuSE's identd</ref>
<ref source="SUSE">19990824 Security hole in netcfg</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/587">587</ref>
<ref source="XF">suse-identd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0747" seq="1999-0747">
<status>Entry</status>
<desc>Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSI.4.10.9908170253560.19291-100000@saturn.psn.net">19990816 Symmetric Multiprocessing (SMP) Vulnerbility in BSDi 4.0.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/589">589</ref>
<ref source="XF">bsdi-smp-dos</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0748" seq="1999-0748">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>Buffer overflows in Red Hat net-tools package.</desc>
<refs>
<ref source="REDHAT">RHSA-1999:017-01</ref>
</refs>
<votes>
<accept count="4">Armstrong, Baker, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<reject count="1">Blake</reject>
</votes>
<comments>
<comment voter="Blake">RHSA-1999:017-01 describes &quot;potential security problem fixed&quot; in the
absence of knowing whether or not the problems actually existed, I don't
think we have an entry here.</comment>
<comment voter="Frech">XF:redhat-net-tool-bo</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0749" seq="1999-0749">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.</desc>
<refs>
<ref source="BUGTRAQ">19990815 telnet.exe heap overflow - remotely exploitable</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-033.mspx">MS99-033</ref>
<ref source="XF">win-ie5-telnet-heap-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/586">586</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0750" seq="1999-0750">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Hotmail security vulnerability - injecting JavaScript using 'STYLE' tag</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/630">630</ref>
</refs>
<votes>
<accept count="1">Levy</accept>
<modify count="2">Frech, Stracener</modify>
<noop count="1">Baker</noop>
</votes>
<comments>
<comment voter="Stracener">Many sites are vulnerable to this problem. I recommend removing the
explicit references to Hotmail and making the description more generic.
Suggest: Javascript can be injected using the STYLE tag in an HTML
formatted e-mail, allowing remote attackers to execute commands on user
accounts.</comment>
<comment voter="Frech">XF:hotmail-html-style-embed</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0751" seq="1999-0751">
<status>Entry</status>
<desc>Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Accept overflow on Netscape Enterprise Server 3.6 SP2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/631">631</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3256">netscape-accept-bo(3256)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0752" seq="1999-0752">
<status>Entry</status>
<desc>Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.</desc>
<refs>
<ref source="BUGTRAQ">19990706 Netscape Enterprise Server SSL Handshake Bug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0753" seq="1999-0753">
<status>Entry</status>
<desc>The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.</desc>
<refs>
<ref source="BUGTRAQ">19990817 Stupid bug in W3-msql</ref>
<ref source="XF">mini-sql-w3-msql-cgi</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/591">591</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0754" seq="1999-0754">
<status>Entry</status>
<desc>The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990511 INN 2.0 and higher. Root compromise potential</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-011.0.txt">CSSA-1999-011.0</ref>
<ref source="SUSE">19990518 Security hole in INN</ref>
<ref source="MISC" url="http://www.redhat.com/corp/support/errata/inn99_05_22.html">http://www.redhat.com/corp/support/errata/inn99_05_22.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/255">255</ref>
<ref source="XF">inn-innconf-env</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0755" seq="1999-0755">
<status>Entry</status>
<desc>Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the &quot;Save password&quot; option.</desc>
<refs>
<ref source="XF">nt-ras-pwcache</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230681">Q230681</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-017.mspx">MS99-017</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0756" seq="1999-0756">
<status>Entry</status>
<desc>ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=10968&amp;Method=Full">ASB99-07</ref>
<ref source="XF" url="http://xforce.iss.net/static/2207.php">coldfusion-admin-dos(2207)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0757" seq="1999-0757">
<status>Candidate</status>
<phase date="20010214">Proposed</phase>
<desc>The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=10969&amp;Method=Full">ASB99-08</ref>
<ref source="XF" url="http://xforce.iss.net/static/2208.php">coldfusion-encryption</ref>
</refs>
<votes>
<accept count="3">Baker, Cole, Frech</accept>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:coldfusion-encryption </comment>
<comment voter="Christey">BUGTRAQ:19990724 Re: New Allaire Security Zone Bulletins and KB Articles
URL:http://www.securityfocus.com/archive/1/19471</comment>
<comment voter="Christey">ADDREF BID:275
URL:http://www.securityfocus.com/bid/275</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0758" seq="1999-0758">
<status>Entry</status>
<desc>Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL.</desc>
<refs>
<ref source="ALLAIRE">ASB99-06</ref>
<ref source="XF">netscape-space-view</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0759" seq="1999-0759">
<status>Entry</status>
<desc>Buffer overflow in FuseMAIL POP service via long USER and PASS commands.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug</ref>
<ref source="CONFIRM" url="http://www.crosswinds.net/~fuseware/faq.html#8">http://www.crosswinds.net/~fuseware/faq.html#8</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/634">634</ref>
<ref source="XF">fuseware-popmail-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0760" seq="1999-0760">
<status>Entry</status>
<desc>Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=11714&amp;Method=Full">ASB99-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/550">550</ref>
<ref source="XF" url="http://xforce.iss.net/static/3288.php">coldfusion-server-cfml-tags</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0761" seq="1999-0761">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-99:05</ref>
<ref source="XF">freebsd-fts-lib-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/644">644</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1074">1074</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0762" seq="1999-0762">
<status>Entry</status>
<desc>When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the &quot;about&quot; protocol to gain access to browser information.</desc>
<refs>
<ref source="XF">netscape-title</ref>
<ref source="BUGTRAQ">19990524 Netscape Communicator JavaScript in &lt;TITLE&gt; security vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0763" seq="1999-0763">
<status>Entry</status>
<desc>NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.</desc>
<refs>
<ref source="NETBSD">1999-010</ref>
<ref source="XF">netbsd-arp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6540">6540</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0764" seq="1999-0764">
<status>Entry</status>
<desc>NetBSD allows ARP packets to overwrite static ARP entries.</desc>
<refs>
<ref source="NETBSD">1999-010</ref>
<ref source="XF">netbsd-arp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6539">6539</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0765" seq="1999-0765">
<status>Entry</status>
<desc>SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.</desc>
<refs>
<ref source="BUGTRAQ">19990619 IRIX midikeys root exploit.</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990501-01-A">19990501-01-A</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/262">262</ref>
<ref source="XF">irix-midikeys</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0766" seq="1999-0766">
<status>Entry</status>
<desc>The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-031.mspx">MS99-031</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240346">Q240346</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/600">600</ref>
<ref source="XF">msvm-verifier-java</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0767" seq="1999-0767">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.</desc>
<refs>
<ref source="SUN">00189</ref>
</refs>
<votes>
<accept count="4">Baker, Blake, Cole, Dik</accept>
<modify count="2">Frech, Stracener</modify>
<reviewing count="2">Christey, Prosser</reviewing>
</votes>
<comments>
<comment voter="Stracener">Add Ref: CIAC: J-069</comment>
<comment voter="Frech">XF:sun-libc-lcmessages</comment>
<comment voter="Prosser">BID 268 is an additional reference for this one as it has info on the Sun
vulnerability.  However, BID 268 also includes AIX in this vulnerability and
refs APARS issued to fix a vulnerability in various 'nixs with the Natural
Language Service environmental variables NSLPATH and PATH_LOCALE depending
on the 'nix, ref CERT CA-97.10, CVE-1999-0041.  However, Georgi Guninski
reported a BO in AIX with LC_MESSAGES + mount, also refed in BID 268, so it
is possible the AIX APARs fix an earlier, similar vulnerability to the Sun
BO in LC_MESSAGES.   This should probably be considered under a different
CAN.  Any ideas? </comment>
<comment voter="Christey">Given that the buffer overflows in CVE-1999-0041 are NLSPATH
and PATH_LOCALE, I'd say that's good evidence that this is not
the same problem.  But a buffer overflow in libc in
LC_MESSAGES... We must ask if these are basically the same
codebase.

ADDREF CIAC:J-069</comment>
<comment voter="Christey">While the description indicates multiple programs, CD:SF-EXEC
does not apply because the vulnerability was in libc, and
rcp and ufsrestore were both statically linked against libc.
Thus CD:SF-LOC applies, and a single candidate is maintained
because the problem occurred in a library.</comment>
<comment voter="Dik">Sun bug 4240566</comment>
<comment voter="Christey">I'm consulting with Casper Dik and Troy Bollinger to see if
this should be combined with the AIX buffer overflows for
LC_MESSAGES; current indications are that they should be
split.</comment>
<comment voter="Christey">For further consultation, consider this post, though it's
associated with CVE-1999-0041:
BUGTRAQ:19970213 Linux NLSPATH buffer overflow
http://www.securityfocus.com/archive/1/6296
Also add &quot;NLSPATH&quot; and &quot;PATH_LOCALE&quot; to the description to
facilitate search.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0768" seq="1999-0768">
<status>Entry</status>
<desc>Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/602">602</ref>
<ref source="REDHAT">RHSA-1999:030-02</ref>
<ref source="SUSE">19990829 Security hole in cron</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0769" seq="1999-0769">
<status>Entry</status>
<desc>Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.</desc>
<refs>
<ref source="REDHAT">RHSA-1999:030-02</ref>
<ref source="CALDERA">CSSA-1999:023.0</ref>
<ref source="SUSE">19990829 Security hole in cron</ref>
<ref source="DEBIAN">19990830 cron</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/611">611</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0770" seq="1999-0770">
<status>Entry</status>
<desc>Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.</desc>
<refs>
<ref source="BUGTRAQ">19990729 Simple DOS attack on FW-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/549">549</ref>
<ref source="CHECKPOINT">ACK DOS ATTACK</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1027">1027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0771" seq="1999-0771">
<status>Entry</status>
<desc>The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19990526 Infosec.19990526.compaq-im.a</ref>
<ref source="COMPAQ">SSRT0612U</ref>
<ref source="XF">management-agent-file-read</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0772" seq="1999-0772">
<status>Entry</status>
<desc>Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.</desc>
<refs>
<ref source="BUGTRAQ">19990527 Re: Infosec.19990526.compaq-im.a (New DoS and correction to my previous post)</ref>
<ref source="COMPAQ">SSRT0612U</ref>
<ref source="XF">management-agent-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0773" seq="1999-0773">
<status>Entry</status>
<desc>Buffer overflow in Solaris lpset program allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9905B&amp;L=bugtraq&amp;P=R2017">19990511 Solaris2.6 and 2.7 lpset overflow</ref>
<ref source="XF">sol-lpset-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0774" seq="1999-0774">
<status>Entry</status>
<desc>Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.</desc>
<refs>
<ref source="BUGTRAQ">19990830 Babcia Padlina Ltd. security advisory: mars_nwe buffer overf</ref>
<ref source="REDHAT">RHSA1999037_01</ref>
<ref source="SUSE">19990916 Security hole in mars nwe</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/617">617</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0775" seq="1999-0775">
<status>Entry</status>
<desc>Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the &quot;established&quot; keyword in an access list.</desc>
<refs>
<ref source="CISCO">19990610 Cisco IOS Software established Access List Keyword Error</ref>
<ref source="XF">cisco-gigaswitch</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0776" seq="1999-0776">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9905&amp;L=NTBUGTRAQ&amp;P=R1533">19990506 &quot;..&quot;-hole in Alibaba 2.0</ref>
<ref source="XF">http-alibaba-dotdot</ref>
</refs>
<votes>
<accept count="4">Frech, Levy, Ozancin, Stracener</accept>
<modify count="1">Baker</modify>
<noop count="6">Armstrong, Blake, Cole, Landfield, LeBlanc, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">This candidate is unconfirmed by the vendor.

Posted by Arne Vidstrom.</comment>
<comment voter="Blake">I'd like to change my vote on this from ACCEPT to NOOP.  I did some
digging and the vendor seems to have discontinued the product, so no
information is available beyond Arne's post.  Unless Andre has a copy
in his archive and can test it, I think we have to leave it out.</comment>
<comment voter="Wall">I agree with Blake.  We have not seen the product and it has been discontinued.</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="Christey">If this is (or was) tested by some tool, we should ACCEPT it.</comment>
<comment voter="Baker">http://www.securityfocus.com/bid/270</comment>
<comment voter="Christey">BID:270
URL:http://www.securityfocus.com/bid/270</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0777" seq="1999-0777">
<status>Entry</status>
<desc>IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have &quot;No Access&quot; permissions.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp">MS99-039</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241407">Q241407</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242559">Q242559</ref>
<ref source="XF">iis-ftp-no-access-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/658">658</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0778" seq="1999-0778">
<status>Entry</status>
<desc>Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.</desc>
<refs>
<ref source="BUGTRAQ">19990626 KSR[T] #011: Accelerated-X</ref>
<ref source="KSRT">011</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/488">488</ref>
<ref source="XF">accelx-display-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0779" seq="1999-0779">
<status>Entry</status>
<desc>Denial of service in HP-UX SharedX recserv program.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9810-086">HPSBUX9810-086</ref>
<ref source="XF">hp-sharedx</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0780" seq="1999-0780">
<status>Entry</status>
<desc>KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-klock-process-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0781" seq="1999-0781">
<status>Entry</status>
<desc>KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-klock-bindir-trojans</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0782" seq="1999-0782">
<status>Entry</status>
<desc>KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-kppp-directory-create</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0783" seq="1999-0783">
<status>Entry</status>
<desc>FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:05</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-057.shtml">I-057</ref>
<ref source="XF">freebsd-nfs-link-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6090">6090</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0784" seq="1999-0784">
<status>Candidate</status>
<phase date="20010214">Proposed</phase>
<desc>Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998/msg00536.html">19980827 NERP DoS attack possible in Oracle</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1999_1/0056.html">19990104 Re: Fw:&quot;NERP&quot; DoS attack possible in Oracle</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1998_4/0764.html">19981228 Oracle8 TNSLSNR DoS</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Cole</noop>
</votes>
<comments>
<comment voter="Frech">XF:oracle-tnslsnr-dos(1551)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0785" seq="1999-0785">
<status>Entry</status>
<desc>The INN inndstart program allows local users to gain root privileges via the &quot;pathrun&quot; parameter in the inn.conf file.</desc>
<refs>
<ref source="BUGTRAQ">19990511 INN 2.0 and higher. Root compromise potential</ref>
<ref source="SUSE">19990518 Security hole in INN</ref>
<ref source="XF">inn-pathrun</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/254">254</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0786" seq="1999-0786">
<status>Entry</status>
<desc>The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19990922 LD_PROFILE local root exploit for solaris 2.6</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/659">659</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0787" seq="1999-0787">
<status>Entry</status>
<desc>The SSH authentication agent follows symlinks via a UNIX domain socket.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93760201002154&amp;w=2">19990917 A few bugs...</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93832856804415&amp;w=2">19990924 [Fwd: Truth about ssh 1.2.27 vulnerability]</ref>
<ref source="XF">ssh-socket-auth-symlink-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/660">660</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0788" seq="1999-0788">
<status>Entry</status>
<desc>Arkiea nlservd allows remote attackers to conduct a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837184228248&amp;w=2">19990924 Multiple vendor Knox Arkiea local root/remote DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/662">662</ref>
<ref source="XF">arkiea-backup-nlserverd-remote-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0789" seq="1999-0789">
<status>Entry</status>
<desc>Buffer overflow in AIX ftpd in the libc library.</desc>
<refs>
<ref source="BUGTRAQ">19990928 Remote bufferoverflow exploit for ftpd from AIX 4.3.2 running on an RS6000</ref>
<ref source="IBM">ERS-SVA-E01-1999:004.1</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-072.shtml">J-072</ref>
<ref source="XF">aix-ftpd-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/679">679</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0790" seq="1999-0790">
<status>Entry</status>
<desc>A remote attacker can read information from a Netscape user's cache via JavaScript.</desc>
<refs>
<ref source="MISC" url="http://home.netscape.com/security/notes/jscachebrowsing.html">http://home.netscape.com/security/notes/jscachebrowsing.html</ref>
<ref source="XF">netscape-javascript</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0791" seq="1999-0791">
<status>Entry</status>
<desc>Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.</desc>
<refs>
<ref source="BUGTRAQ">19991006 KSR[T] Advisories #012: Hybrid Network's Cable Modems</ref>
<ref source="KSRT">012</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/695">695</ref>
<ref source="XF">hybrid-anon-cable-modem-reconfig</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0792" seq="1999-0792">
<status>Candidate</status>
<phase date="20000827">Modified</phase>
<desc>ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.</desc>
<refs>
<ref source="MISC" url="http://www2.merton.ox.ac.uk/~security/rootshell/0022.html">http://www2.merton.ox.ac.uk/~security/rootshell/0022.html</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Stracener</modify>
<noop count="1">Christey</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Stracener">Change the Ref to read: ROOTSHELL: Osicom Technologies ROUTERmate
Security
Advisory</comment>
<comment voter="Frech">XF:routermate-snmp-community</comment>
<comment voter="Christey">BUGTRAQ:19980914 [rootshell] Security Bulletin #23
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90581019105693&amp;w=2</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0793" seq="1999-0793">
<status>Entry</status>
<desc>Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-043.mspx">MS99-043</ref>
<ref source="XF">ie-java-redirect</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0794" seq="1999-0794">
<status>Entry</status>
<desc>Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-044.mspx">MS99-044</ref>
<ref source="XF">excel-sylk</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241900">Q241900</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241901">Q241901</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241902">Q241902</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0795" seq="1999-0795">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.</desc>
<refs>
<ref source="NAI">NAI-27</ref>
</refs>
<votes>
<accept count="2">Baker, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Ozancin</noop>
</votes>
<comments>
<comment voter="Frech">XF:sun-nisplus</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0796" seq="1999-0796">
<status>Entry</status>
<desc>FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks.</desc>
<refs>
<ref source="FREEBSD">SA-98.03</ref>
<ref source="XF">freebsd-ttcp-spoof</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6089">6089</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0797" seq="1999-0797">
<status>Entry</status>
<desc>NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.</desc>
<refs>
<ref source="ISS">19980629 Distributed DoS attack against NIS/NIS+ based networks.</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-070.shtml">I-070</ref>
<ref source="XF">sun-nis-nisplus</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0798" seq="1999-0798">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91278867118128&amp;w=2">19981204 bootpd remote vulnerability</ref>
</refs>
<votes>
<accept count="3">Baker, Ozancin, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Christey">Is CVE-1999-0389 a duplicate of CVE-1999-0798?  CVE-1999-0389
has January 1999 dates associated with it, while CVE-1999-0798
was reported in late December.

http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91278867118128&amp;w=2

SCO appears to have acknowledged this as well:
ftp://ftp.sco.com/SSE/security_bulletins/SB-99.01a

The poster also claims that OpenBSD fixed this as well.</comment>
<comment voter="Frech">XF:bootp-remote-bo</comment>
<comment voter="Christey">Further analysis indicates that this is a duplicate of CVE-1999-0799</comment>
<comment voter="CHANGE">[Christey changed vote from REJECT to NOOP]</comment>
<comment voter="Christey">What was I thinking?  Brian Caswell pointed out that this is
*not* the same bug as CVE-1999-0799.  As reported in the
1998 Bugtraq post, the bug is in bootpd.c, and is related
to providing an htype value that is used as an index
into an array, and exceeds the intended boundaries of that
array.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0799" seq="1999-0799">
<status>Entry</status>
<desc>Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.</desc>
<refs>
<ref source="BUGTRAQ">19970725 Exploitable buffer overflow in bootpd (most unices)</ref>
<ref source="XF">bootpd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0800" seq="1999-0800">
<status>Entry</status>
<desc>The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=9602&amp;Method=Full">ASB99-05</ref>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00332.html">19990211 ACFUG List: Alert: Allaire Forums GetFile bug</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1748">allaire-forums-file-read(1748)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/944">944</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0801" seq="1999-0801">
<status>Entry</status>
<desc>BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2075.php">bmc-patrol-frames(2075)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0802" seq="1999-0802">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.</desc>
<refs>
<ref source="BUGTRAQ">19990503 MSIE 5 FAVICON BUG</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx">MS99-018</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231450">Q231450</ref>
<ref source="XF">ie-favicon</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0803" seq="1999-0803">
<status>Entry</status>
<desc>The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92765973207648&amp;w=2">19990525 IBM eNetwork Firewall for AIX</ref>
<ref source="XF">ibm-enfirewall-tmpfiles</ref>
<ref source="OSVDB" url="http://www.osvdb.org/962">962</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0804" seq="1999-0804">
<status>Entry</status>
<desc>Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.</desc>
<refs>
<ref source="BUGTRAQ">19990601 Linux kernel 2.2.x vulnerability/exploit</ref>
<ref source="DEBIAN">19990607</ref>
<ref source="CALDERA">CSSA-1999:013</ref>
<ref source="SUSE">19990602 Denial of Service on the 2.2 kernel</ref>
<ref source="REDHAT">19990603 Kernel Update</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/302">302</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0805" seq="1999-0805">
<status>Candidate</status>
<phase date="20010214">Proposed</phase>
<desc>Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1999_2/0439.html">19990512 DoS with Netware 4.x's TTS</ref>
<ref source="XF" url="http://xforce.iss.net/static/2184.php">novell-tts-dos</ref>
</refs>
<votes>
<accept count="2">Baker, Frech</accept>
<noop count="2">Christey, Cole</noop>
</votes>
<comments>
<comment voter="Christey">BID:276
URL:http://www.securityfocus.com/vdb/bottom.html?vid=276</comment>
<comment voter="Frech">XF:novell-tts-dos</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0806" seq="1999-0806">
<status>Entry</status>
<desc>Buffer overflow in Solaris dtprintinfo program.</desc>
<refs>
<ref source="BUGTRAQ">19990510 Solaris2.6,2.7 dtprintinfo exploits</ref>
<ref source="XF">cde-dtprintinfo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6552">6552</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0807" seq="1999-0807">
<status>Entry</status>
<desc>The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.</desc>
<refs>
<ref source="XF">netscape-dirsvc-password</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0808" seq="1999-0808">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925960&amp;w=2">19980518 DHCP 1.0 and 2.0 SECURITY ALERT! (fwd)</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-053.shtml">I-053</ref>
<ref source="MISC" url="ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz">ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz</ref>
</refs>
<votes>
<accept count="4">Armstrong, Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:dhcp-remote-dos(7248)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0809" seq="1999-0809">
<status>Entry</status>
<desc>Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to &quot;Only accept cookies originating from the same server as the page being viewed&quot;.</desc>
<refs>
<ref source="BUGTRAQ">19990709 Communicator 4.[56]x, JavaScript used to bypass cookie settings</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0810" seq="1999-0810">
<status>Entry</status>
<desc>Denial of service in Samba NETBIOS name service daemon (nmbd).</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="DEBIAN">19990731</ref>
<ref source="DEBIAN">19990804</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0811" seq="1999-0811">
<status>Entry</status>
<desc>Buffer overflow in Samba smbd program via a malformed message command.</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
<ref source="DEBIAN">19990731 Samba</ref>
<ref source="XF">samba-message-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/536">536</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0812" seq="1999-0812">
<status>Entry</status>
<desc>Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="DEBIAN">19990731</ref>
<ref source="DEBIAN">19990804</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0813" seq="1999-0813">
<status>Entry</status>
<desc>Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">19990810 Severe bug in cfingerd before 1.4.0</ref>
<ref source="BUGTRAQ">19980724 CFINGERD root security hole</ref>
<ref source="DEBIAN">19990814</ref>
<ref source="XF">cfingerd-privileges</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0814" seq="1999-0814">
<status>Entry</status>
<desc>Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-027.html">RHSA-1999:027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0815" seq="1999-0815">
<status>Entry</status>
<desc>Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q196/2/70.asp">Q196270</ref>
<ref source="XF" url="http://xforce.iss.net/static/1974.php">nt-snmpagent-leak(1974)</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:952">oval:org.mitre.oval:def:952</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0816" seq="1999-0816">
<status>Candidate</status>
<phase date="20000313">Modified</phase>
<desc>The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9805B&amp;L=bugtraq&amp;P=R1621">19980510 Security Vulnerability in Motorola CableRouters</ref>
<ref source="XF">motorola-cable-default-pass</ref>
</refs>
<votes>
<accept count="3">Baker, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, LeBlanc</noop>
</votes>
<comments>
<comment voter="Christey">This candidate is unconfirmed by the vendor.</comment>
<comment voter="Frech">XF:motorola-cable-default-pass</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0817" seq="1999-0817">
<status>Entry</status>
<desc>Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.</desc>
<refs>
<ref source="SUSE">19990915 Security hole in lynx</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0818" seq="1999-0818">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38433B7F5A.53F4SHADOWPENGUIN@fox.nightland.net">19991130 another hole of Solaris7 kcms_configure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/831">831</ref>
</refs>
<votes>
<accept count="2">Armstrong, Stracener</accept>
<modify count="4">Cole, Dik, Frech, Prosser</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Cole">This can cause code to be executed.</comment>
<comment voter="Frech">XF:sol-kcms-conf-netpath-bo</comment>
<comment voter="Dik">the bug has nothing to do with kcms_configure; it's a bug
in libnsl.so.  All set-uid executables that trigger this code path are
vulnerable.  Sun bug 4295834; fixed in Solaris 8.</comment>
<comment voter="Prosser">Okay, I am confused.  Based on Casper's comments and checking
on the Sun patch site, I found the 4295834 bug(4295834 NETPATH security
problem in libnsl) fixed in  SunOS 5.4, Patch 101974-37(x86) 101973 (sparc).
Multiple libnsl vulnerabilities was first reported in an 98 Sun Bulletin
#00172 for 5.4 up through 2.6.   Was this NETPATH a problem that resurfaced
in 7 (looks like in 5.4 as well) and was fixed in 8?</comment>
<comment voter="Christey">Need to dig up my offline email on this.</comment>
<comment voter="Christey">May be a duplicate of CVE-1999-0321, whose sole reference
(XF:sun-kcms-configure-bo) no longer exists.  Also examine
BID:452 and
BUGTRAQ:19981223 Merry Christmas to Sun! (Was: L0pht NFR N-Code
Modules Updated)

which are the same as XF:sol-kcms-conf-p-bo(3652), which could
be the new name for XF:sun-kcms-configure-bo.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0819" seq="1999-0819">
<status>Entry</status>
<desc>NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.</desc>
<refs>
<ref source="NTBUGTRAQ">19991130 NTmail and VRFY</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94398141118586&amp;w=2">19991130 NTmail and VRFY</ref>
<ref source="XF">nt-mail-vrfy</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0820" seq="1999-0820">
<status>Entry</status>
<desc>FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/838">838</ref>
<ref source="XF">freebsd-seyon-dir-add</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5996">5996</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0821" seq="1999-0821">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/838">838</ref>
</refs>
<votes>
<accept count="2">Armstrong, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Cole</reject>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Cole">I would combine this with the previous.  To me the general
vulnerabilities are similar it is just the end result that changes.</comment>
<comment voter="Frech">XF:freebsd-seyon-setgid</comment>
<comment voter="Christey">ADDREF? CALDERA:CSSA-1999-037.0</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0822" seq="1999-0822">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.</desc>
<refs>
<ref source="BUGTRAQ">19991130 serious Qpopper 3.0 vulnerability</ref>
<ref source="BUGTRAQ">19991130 qpop3.0b20 and below - notes and exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/830">830</ref>
</refs>
<votes>
<accept count="4">Armstrong, Baker, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:qpopper-auth-bo</comment>
<comment voter="Christey">ADDREF? DEBIAN:19991215 buffer overflow in qpopper v3.0
ADDREF XF:qpopper-auth-bo</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0823" seq="1999-0823">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/839">839</ref>
<ref source="XF">freebsd-xmindpath</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1150">1150</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0824" seq="1999-0824">
<status>Entry</status>
<desc>A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/833">833</ref>
<ref source="NTBUGTRAQ">19991130 SUBST problem</ref>
<ref source="BUGTRAQ">19991130 Subst.exe carelessness (fwd)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0825" seq="1999-0825">
<status>Candidate</status>
<phase date="20000121">Modified</phase>
<desc>The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.</desc>
<refs>
<ref source="BUGTRAQ">19991203 UnixWare read/modify users' mail</ref>
<ref source="BUGTRAQ">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BUGTRAQ">19991223 FYI, SCO Security patches available.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/849">849</ref>
</refs>
<votes>
<accept count="4">Armstrong, Baker, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:sco-mail-permissions</comment>
<comment voter="Christey">ADDREF ftp://ftp.sco.com/SSE/security_bulletins/SB-99.25a</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0826" seq="1999-0826">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD angband allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/840">840</ref>
<ref source="XF">angband-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1151">1151</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0827" seq="1999-0827">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>By default, Internet Explorer 5.0 and other versions enables the &quot;Navigate sub-frames across different domains&quot; option, which allows frame spoofing.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Default IE 5.0 security settings allow frame spoofing</ref>
</refs>
<votes>
<accept count="4">Armstrong, Baker, LeBlanc, Stracener</accept>
<modify count="2">Cole, Frech</modify>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Cole">The BID is 855.  If I have the right vulnerability, this allows an
attacker to access URL's of there choosing which could lead to a compromise
of private information.</comment>
<comment voter="Frech">XF:http-frame-spoof
Question: Similar vulnerability to MS98-020 / CVE-1999-0869?</comment>
<comment voter="LeBlanc">MSRC tells me this is patched in MS00-009</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0828" seq="1999-0828">
<status>Candidate</status>
<phase date="20000121">Modified</phase>
<desc>UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.</desc>
<refs>
<ref source="BUGTRAQ">19991203 UnixWare and the dacread permission</ref>
<ref source="BUGTRAQ">19991204 UnixWare pkg* command exploits</ref>
<ref source="BUGTRAQ">19991223 FYI, SCO Security patches available.</ref>
<ref source="BUGTRAQ">19991220 SCO OpenServer Security Status</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/853">853</ref>
</refs>
<votes>
<accept count="3">Armstrong, Baker, Stracener</accept>
<modify count="2">Cole, Frech</modify>
<reviewing count="2">Christey, Prosser</reviewing>
</votes>
<comments>
<comment voter="Cole">This is BID 850.</comment>
<comment voter="Christey">See comments on CVE-1999-0988.  Perhaps these two should be
merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a
loosely alludes to this problem; the README for patch SSE053
effectively confirms it.</comment>
<comment voter="Frech">XF:sco-pkg-dacread-fileread</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0829" seq="1999-0829">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>HP Secure Web Console uses weak encryption.</desc>
<refs>
<ref source="BUGTRAQ">19991201 HP Secure Web Console</ref>
</refs>
<votes>
<accept count="2">Armstrong, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Cole</noop>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Cole">I could not find details on this using the above references.</comment>
<comment voter="Frech">XF:hp-secure-console</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0830" seq="1999-0830">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Buffer overflow in SCO UnixWare Xsco command via a long argument.</desc>
<refs>
<ref source="BUGTRAQ">19991126 [w00giving '99 #6]: UnixWare 7's Xsco</ref>
</refs>
<votes>
<accept count="3">Armstrong, Baker, Stracener</accept>
<modify count="3">Cole, Frech, Prosser</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Cole">This is BID 824 and the BUGTRAQ reference is 19991125.</comment>
<comment voter="Frech">XF:sco-unixware-xsco</comment>
<comment voter="Christey">Confirmed by vendor, albeit vaguely:
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2
</comment>
<comment voter="Prosser">agree with Steve on vendor confirmation, however not sure the
fix ref'd in BID 824 (SSE041) is right.  It lists fixes for libnsl and
tcpip.so, nothing about xsco.  SSE050b
(ftp://ftp.sco.com/SSE/security_bulletins/SB-99.26b) fixes a buffer overflow
in xsco on OpenServer (the vendor message Steve refers to) but not the
UnixWare vulnerability reported on Bugtraq and in BID824. Anyone more
familar with SCO shed some light on this? Are they the same codebase so fix
would be same?  From the SCO site it seems the UnixWare and OpenSever
products are similar but have differences.</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="Christey">BID:824
http://www.securityfocus.com/bid/824</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0831" seq="1999-0831">
<status>Entry</status>
<desc>Denial of service in Linux syslogd via a large number of connections.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-035.0.txt">CSSA-1999-035.0</ref>
<ref source="REDHAT">RHSA1999055-01</ref>
<ref source="SUSE">19991118 syslogd-1.3.33 (a1)</ref>
<ref source="BUGTRAQ">19991130 [david@slackware.com: New Patches for Slackware 4.0 Available]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/809">809</ref>
<ref source="XF">slackware-syslogd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0832" seq="1999-0832">
<status>Entry</status>
<desc>Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.20.9911091058140.12964-100000@mail.zigzag.pl">19991109 undocumented bugs - nfsd</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/1999/19991111">19991111 buffer overflow in nfs server</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_29.html">19991110 Security hole in nfs-server &lt; 2.2beta47 within nkita</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-033.0.txt">CSSA-1999-033.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/rh42-errata-general.html#NFS">RHSA-1999:053-01</ref>
<ref source="BUGTRAQ">19991130 [david@slackware.com: New Patches for Slackware 4.0 Available]</ref>
<ref source="XF">linux-nfs-maxpath-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/782">782</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0833" seq="1999-0833">
<status>Entry</status>
<desc>Buffer overflow in BIND 8.2 via NXT records.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-nxt-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0834" seq="1999-0834">
<status>Entry</status>
<desc>Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.</desc>
<refs>
<ref source="BUGTRAQ">19991201 Security Advisory: Buffer overflow in RSAREF2</ref>
<ref source="BUGTRAQ">19991202 OpenBSD sslUSA26 advisory (Re: CORE-SDI: Buffer overflow in RSAREF2)</ref>
<ref source="CERT">CA-99-15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/843">843</ref>
<ref source="XF">rsaref-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0835" seq="1999-0835">
<status>Entry</status>
<desc>Denial of service in BIND named via malformed SIG records.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="XF">bind-sigrecord-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0836" seq="1999-0836">
<status>Entry</status>
<desc>UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991202160111.20553.qmail@nwcst282.netaddress.usa.net">19991202 UnixWare 7 uidadmin exploit + discussion</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.22a">SB-99.22a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/842">842</ref>
<ref source="XF">unixware-uid-admin</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0837" seq="1999-0837">
<status>Entry</status>
<desc>Denial of service in BIND by improperly closing TCP sessions via so_linger.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="XF">bind-solinger-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0838" seq="1999-0838">
<status>Entry</status>
<desc>Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.</desc>
<refs>
<ref source="BUGTRAQ">19991202 Remote DoS Attack in Serv-U FTP-Server v2.5a Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/859">859</ref>
<ref source="XF">servu-ftp-site-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0839" seq="1999-0839">
<status>Entry</status>
<desc>Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.</desc>
<refs>
<ref source="NTBUGTRAQ">19991130 Windows NT Task Scheduler vulnerability allows user to administrator elevation</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-051.mspx">MS99-051</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246972">Q246972</ref>
<ref source="XF">ie-task-scheduler-privs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/828">828</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0840" seq="1999-0840">
<status>Candidate</status>
<phase date="20071022">Modified</phase>
<desc>Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/1999-q4/0122.html">19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref>
<ref source="MISC" url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/832">832</ref>
<ref source="MISC" url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3579">solaris-dtmail-overflow(3579)</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3580">solaris-dtmailpr-overflow(3580)</ref>
</refs>
<votes>
<accept count="4">Armstrong, Baker, Dik, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Cole</noop>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Cole">I went to 1129 and it looks like a reference for a different
vulnerability.</comment>
<comment voter="Frech">In the description, should dtmailptr be dtmailpr?
XF:solaris-dtmailpr-overflow
XF:solaris-dtmail-overflow</comment>
<comment voter="Dik">sun bug: 4166321</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0841" seq="1999-0841">
<status>Candidate</status>
<phase date="20071022">Modified</phase>
<desc>Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/1999-q4/0122.html">19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref>
<ref source="MISC" url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/832">832</ref>
<ref source="MISC" url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3732">cde-mailtool-bo(3732)</ref>
</refs>
<votes>
<accept count="5">Armstrong, Baker, Cole, Dik, Stracener</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:cde-mailtool-bo</comment>
<comment voter="Dik">bug 4163471
(Root access is only possible when mail is send to root and he
uses dtmail to read it)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0842" seq="1999-0842">
<status>Entry</status>
<desc>Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="NTBUGTRAQ">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEAFCBAA.labs@ussrback.com">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/827">827</ref>
<ref source="XF">symantec-mail-dir-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1144">1144</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0843" seq="1999-0843">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.</desc>
<refs>
<ref source="BUGTRAQ">19991104 Cisco NAT DoS (VD#1)</ref>
<ref source="BUGTRAQ">19991128 Re: Cisco NAT DoS (VD#1)</ref>
</refs>
<votes>
<accept count="3">Balinsky, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Armstrong, Baker</noop>
<reviewing count="3">Christey, Prosser, Ziese</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:cisco-nat-dos</comment>
<comment voter="Christey">Mike Prosser's REVIEWING vote expires July 17, 2000</comment>
<comment voter="Ziese">After reviewing
http://www.cisco.com/warp/public/707/iostelnetopt-pub.shtml 
I can not confirm this exists unless it's restructred to
describe a problem against IOS per se; not NAT per se.  I am
reviewing this and it may take some time.</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="Christey">Not sure if Kevin's suggested reference really describes this
one.  However, a followup email by Jim Duncan of Cisco does
acknowledge the problem as discussed in the Bugtraq post:
http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=94385601831585&amp;w=2
The original post is:
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94184947504814&amp;w=2

It could be that the researcher believed that the problem was
NAT, but in fact it wasn't.

I need to follow up with Ziese/Balinsky on this one.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0844" seq="1999-0844">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Denial of service in MDaemon WorldClient and WebConfig services via a long URL.</desc>
<refs>
<ref source="NTBUGTRAQ">19991124 Remote DoS Attack in WorldClient Server v2.0.0.0 Vulnerability</ref>
<ref source="BUGTRAQ">19991130 Fwd: RE: Multiples Remotes DoS Attacks in MDaemon Server v2.8.5.0 Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/823">823</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/820">820</ref>
</refs>
<votes>
<accept count="2">Baker, Stracener</accept>
<modify count="2">Cole, Frech</modify>
<noop count="1">Armstrong</noop>
<recast count="1">Christey</recast>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Cole">823 and 820 are two different vulnerabilities and should be
separated out.  They are both buffer overflows but accomplish it in a
different fashion and the end exploit is different.</comment>
<comment voter="Frech">(RECAST?)
XF:mdaemon-worldclient-dos
XF:mdaemon-webconfig-dos
Recast request: This is really two services exhibiting the same problem.</comment>
<comment voter="Christey">as suggested by others.

Also see confirmation at:
http://mdaemon.deerfield.com/helpdesk/hotfix.cfm</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0845" seq="1999-0845">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Buffer overflow in SCO su program allows local users to gain root access via a long username.</desc>
<refs>
<ref source="BUGTRAQ">19991126 [w00giving '99 #5 and w00news]: UnixWare 7's su</ref>
<ref source="SCO">99.19</ref>
<ref source="BUGTRAQ">19991128 SCO su patches</ref>
</refs>
<votes>
<accept count="4">Armstrong, Cole, Prosser, Stracener</accept>
<modify count="1">Frech</modify>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">DUPE CVE-1999-0317?</comment>
<comment voter="Frech">XF:sco-su-username-bo</comment>
<comment voter="Christey">ADDREF BID:826
CONFIRM:ftp://ftp.sco.com/SSE/sse039.tar.Z</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0846" seq="1999-0846">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Denial of service in MDaemon 2.7 via a large number of connection attempts.</desc>
<refs>
<ref source="BUGTRAQ">19991129 MDaemon 2.7 J DoS</ref>
<ref source="BUGTRAQ">19991130 Fwd: RE: Multiples Remotes DoS Attacks in MDaemon Server v2.8.5.0 Vulnerability</ref>
</refs>
<votes>
<accept count="5">Armstrong, Baker, Cole, Prosser, Stracener</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:mdaemon-dos</comment>
<comment voter="Christey">CVE-1999-0844 is confirmed by MDaemon at
http://mdaemon.deerfield.com/helpdesk/hotfix.cfm but there
is no apparent confirmation for this problem, even
though it was posted the same day.</comment>
<comment voter="Prosser">Looks like from a follow-on message on Bugtraq from Nobuo
&lt;http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-11-28&amp;msg=199912011604.HJI39569.BX-NOJ@lac.co.jp&gt; Deerfield sent a reply about the
DoS problems in MDaemon 2.8.5, that also talks about fixing the 2.7 J DoS
that Nobuo initially reported. Can't find the original message, so may have
been limited distro. Looks like an upgrade to the latest release might be
the final solution here.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0847" seq="1999-0847">
<status>Entry</status>
<desc>Buffer overflow in free internet chess server (FICS) program, xboard.</desc>
<refs>
<ref source="BUGTRAQ">19991129 FICS buffer overflow</ref>
<ref source="XF">fics-board-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0848" seq="1999-0848">
<status>Entry</status>
<desc>Denial of service in BIND named via consuming more than &quot;fdmax&quot; file descriptors.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-fdmax-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0849" seq="1999-0849">
<status>Entry</status>
<desc>Denial of service in BIND named via maxdname.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-maxdname-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0850" seq="1999-0850">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>The default permissions for Endymion MailMan allow local users to read email or modify files.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/845">845</ref>
<ref source="BUGTRAQ">19991202 Insecure default permissions for MailMan Professional Edition, version 3.0.18</ref>
</refs>
<votes>
<accept count="2">Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Armstrong, Baker</noop>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:endymion-mailman-perms</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0851" seq="1999-0851">
<status>Entry</status>
<desc>Denial of service in BIND named via naptr.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-naptr-dos</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0852" seq="1999-0852">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/844">844</ref>
<ref source="BUGTRAQ">19991202 WebSphere protections from installation</ref>
</refs>
<votes>
<accept count="3">Armstrong, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:websphere-protect</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0853" seq="1999-0853">
<status>Entry</status>
<desc>Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/847">847</ref>
<ref source="ISS">19991201 Buffer Overflow in Netscape Enterprise and FastTrack Authentication Procedure</ref>
<ref source="XF">netscape-fasttrack-auth-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0854" seq="1999-0854">
<status>Entry</status>
<desc>Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Ultimate Bulletin Board v5.3x? Bug</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref>
<ref source="CONFIRM" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref>
<ref source="XF">http-ultimate-bbs</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0855" seq="1999-0855">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Buffer overflow in FreeBSD gdc program.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/834">834</ref>
<ref source="BUGTRAQ">19991130 FreeBSD 3.3 gated-3.1.5 local exploit</ref>
</refs>
<votes>
<accept count="3">Armstrong, Prosser, Stracener</accept>
<modify count="2">Cole, Frech</modify>
<noop count="2">Baker, Christey</noop>
</votes>
<comments>
<comment voter="Cole">The BID is 834 and the reference is 19991201 not 1130.</comment>
<comment voter="Frech">XF:freebsd-gdc-bo</comment>
<comment voter="Christey">ADDREF BID:780 ?</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0856" seq="1999-0856">
<status>Entry</status>
<desc>login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.</desc>
<refs>
<ref source="BUGTRAQ">19991202 Slackware 7.0 - login bug</ref>
<ref source="XF">slackware-remote-login</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0857" seq="1999-0857">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>FreeBSD gdc program allows local users to modify files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991130 FreeBSD 3.3 gated-3.1.5 local exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/835">835</ref>
</refs>
<votes>
<accept count="3">Armstrong, Prosser, Stracener</accept>
<modify count="2">Cole, Frech</modify>
<noop count="1">Baker</noop>
</votes>
<comments>
<comment voter="Cole">This is via debug output.</comment>
<comment voter="Frech">XF:freebsd-gdc</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0858" seq="1999-0858">
<status>Entry</status>
<desc>Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-054.mspx">MS99-054</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q247333">Q247333</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/846">846</ref>
<ref source="XF">ie-wpad-proxy-settings</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0859" seq="1999-0859">
<status>Entry</status>
<desc>Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Solaris 2.x chkperm/arp vulnerabilities</ref>
<ref source="SUNBUG">4296166</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/837">837</ref>
<ref source="XF">sol-arp-parse</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6994">6994</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0860" seq="1999-0860">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Solaris 2.x chkperm/arp vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/837">837</ref>
</refs>
<votes>
<accept count="2">Armstrong, Stracener</accept>
<modify count="2">Dik, Frech</modify>
<noop count="2">Baker, Christey</noop>
<reject count="1">Cole</reject>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Cole">This is the same as the pervious.</comment>
<comment voter="Frech">XF:sol-chkperm-vmsys</comment>
<comment voter="Dik">include reference to Sun bug 4296167</comment>
<comment voter="Christey">Remove BID:837, which is for arp, not chkperm</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0861" seq="1999-0861">
<status>Entry</status>
<desc>Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-053.mspx">MS99-053</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q244613">Q244613</ref>
<ref source="XF">iis-ssl-isapi-filter</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0862" seq="1999-0862">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.</desc>
<refs>
<ref source="BUGTRAQ">19991202 PostgreSQL RPM's permission problems</ref>
</refs>
<votes>
<accept count="3">Armstrong, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Prosser</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:postgresql-insecure-perms</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0863" seq="1999-0863">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.</desc>
<refs>
<ref source="BUGTRAQ">19970617 Seyon vulnerability - IRIX</ref>
<ref source="BUGTRAQ">19991108 FreeBSD 3.3's seyon vulnerability</ref>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
</refs>
<votes>
<accept count="4">Armstrong, Cole, Prosser, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:freebsd-seyon-bo</comment>
<comment voter="Christey">ADDREF? CALDERA:CSSA-1999-037.0</comment>
<comment voter="Christey">May be multiple bugs here, or a single library problem.
CD:SF-LOC needs to be resolved before determining if this
candidate should be SPLIT.  Also see CVE-1999-0821.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0864" seq="1999-0864">
<status>Entry</status>
<desc>UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991203020720.13115.qmail@nwcst289.netaddress.usa.net">19991202 UnixWare coredumps follow symlinks</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref>
<ref source="XF">sco-coredump-symlink</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/851">851</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0865" seq="1999-0865">
<status>Entry</status>
<desc>Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94426440413027&amp;w=2">19991203 CommuniGatePro 3.1 for NT DoS</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94454565726775&amp;w=2">19991203 CommuniGatePro 3.1 for NT Buffer Overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/860">860</ref>
<ref source="XF">communigate-pro-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0866" seq="1999-0866">
<status>Entry</status>
<desc>Buffer overflow in UnixWare xauto program allows local users to gain root privilege.</desc>
<refs>
<ref source="BUGTRAQ">19991203 UnixWare gain root with non-su/gid binaries</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.24a">SB-99.24a</ref>
<ref source="XF">sco-xauto-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/848">848</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0867" seq="1999-0867">
<status>Entry</status>
<desc>Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-029.mspx">MS99-029</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238349">Q238349</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-058.shtml">J-058</ref>
<ref source="XF">http-iis-malformed-header</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/579">579</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0868" seq="1999-0868">
<status>Entry</status>
<desc>ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.</desc>
<refs>
<ref source="CERT">CA-97.08</ref>
<ref source="XF">inn-ucbmail-shell-meta</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0869" seq="1999-0869">
<status>Entry</status>
<desc>Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx">MS98-020</ref>
<ref source="MSKB">167614</ref>
<ref source="XF">http-frame-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0870" seq="1999-0870">
<status>Entry</status>
<desc>Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-015.mspx">MS98-015</ref>
<ref source="MSKB">169245</ref>
<ref source="XF">ie-usp-cuartango</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0871" seq="1999-0871">
<status>Entry</status>
<desc>Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the &quot;Cross Frame Navigate&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-013.mspx">MS98-013</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7837">7837</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3668">ie-crossframe-file-read(3668)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0872" seq="1999-0872">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/759">759</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/611">611</ref>
<ref source="REDHAT">RHSA-1999:030-02</ref>
</refs>
<votes>
<modify count="2">Cole, Frech</modify>
<noop count="1">Baker</noop>
<reject count="3">Blake, Christey, Stracener</reject>
</votes>
<comments>
<comment voter="Cole">611 is the mail to listed above but 759 is for the mail from and
should be listed as a separate vulenrability.</comment>
<comment voter="Blake">This does not appear materially different from CVE-1999-0768</comment>
<comment voter="Christey">This is an apparent duplicate of CVE-1999-0768.
REDHAT:RHSA-1999:030-02 describes two issues, one of which is
CVE-1999-0768, and the other is CVE-1999-0769.</comment>
<comment voter="Stracener">This is a duplicate of candidate CVE-1999-0768.</comment>
<comment voter="Frech">XF:cron-sendmail-bo-root</comment>
<comment voter="Christey">BID:759 is improperly assigned to this candidate and doesn't
even describe it.  It may have been inadvertently copied
from CVE-1999-0873.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0873" seq="1999-0873">
<status>Entry</status>
<desc>Buffer overflow in Skyfull mail server via MAIL FROM command.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/759">759</ref>
<ref source="XF">skyfull-mail-from-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0874" seq="1999-0874">
<status>Entry</status>
<desc>Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-019.asp">MS99-019</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234905">Q234905</ref>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD06081999.html">AD06081999</ref>
<ref source="CERT">CA-99-07</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-048.shtml">J-048</ref>
<ref source="XF">iis-htr-overflow</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:915">oval:org.mitre.oval:def:915</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0875" seq="1999-0875">
<status>Entry</status>
<desc>DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.</desc>
<refs>
<ref source="L0PHT">19990811</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q216141">Q216141</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/578">578</ref>
<ref source="XF">irdp-gateway-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0876" seq="1999-0876">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 4.0 via EMBED tag.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q185959">Q185959</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0877" seq="1999-0877">
<status>Entry</status>
<desc>Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243638">Q243638</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-042.mspx">MS99-042</ref>
<ref source="XF">ie-iframe-exec</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0878" seq="1999-0878">
<status>Entry</status>
<desc>Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.</desc>
<refs>
<ref source="COMPAQ">SSRT0622</ref>
<ref source="REDHAT">RHSA1999031_01</ref>
<ref source="AUSCERT">AA-1999.01</ref>
<ref source="CERT">CA-99-13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/599">599</ref>
<ref source="XF">wu-ftpd-dir-name</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0879" seq="1999-0879">
<status>Entry</status>
<desc>Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.</desc>
<refs>
<ref source="CERT">CA-99-13</ref>
<ref source="XF">wuftp-message-file-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0880" seq="1999-0880">
<status>Entry</status>
<desc>Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.</desc>
<refs>
<ref source="CERT">CA-99-13</ref>
<ref source="XF">wuftp-site-newer-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0881" seq="1999-0881">
<status>Entry</status>
<desc>Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991025 Falcon Web Server</ref>
<ref source="BINDVIEW">Falcon Web Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/743">743</ref>
<ref source="XF">falcon-path-parsing</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1127">1127</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0882" seq="1999-0882">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.</desc>
<refs>
<ref source="BUGTRAQ">19991025 Falcon Web Server</ref>
<ref source="BINDVIEW">Falcon Web Server</ref>
</refs>
<votes>
<accept count="3">Baker, Blake, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Armstrong, Cole</noop>
</votes>
<comments>
<comment voter="Frech">XF:falcon-server-long-filename</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0883" seq="1999-0883">
<status>Entry</status>
<desc>Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine.</desc>
<refs>
<ref source="BUGTRAQ">19991024 RFP9905: Zeus webserver remote root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1126">1126</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3380">zeus-remote-root(3380)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0884" seq="1999-0884">
<status>Entry</status>
<desc>The Zeus web server administrative interface uses weak encryption for its passwords.</desc>
<refs>
<ref source="BUGTRAQ">19991024 RFP9905: Zeus webserver remote root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8186">8186</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3833">zeus-weak-password(3833)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0885" seq="1999-0885">
<status>Candidate</status>
<phase date="20000313">Modified</phase>
<desc>Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-11-01&amp;msg=01BF261F.928821E0.kerb@fnusa.com">19991103 More Alibaba Web Server problems...</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/770">770</ref>
<ref source="XF">alibaba-url-file-manipulation</ref>
</refs>
<votes>
<accept count="2">Baker, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="5">Armstrong, Blake, Christey, Cole, LeBlanc</noop>
</votes>
<comments>
<comment voter="Christey">This candidate is unconfirmed by the vendor.</comment>
<comment voter="Blake">Same as CVE-1999-0776.</comment>
<comment voter="Frech">XF:alibaba-url-file-manipulation</comment>
<comment voter="Christey">CD:SF-LOC and CD:SF-EXEC may say to merge this candidate with
the problems described in:
BUGTRAQ:20000718 Multiple bugs in Alibaba 2.0
URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html

If so, then ADDREF BID:1485 as well.</comment>
<comment voter="Christey">Include the names of the affected CGI's, including tst.bat,
get32.exe, alibaba.pl, etc.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0886" seq="1999-0886">
<status>Entry</status>
<desc>The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242294">Q242294</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-041.mspx">MS99-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/645">645</ref>
<ref source="XF">nt-rasman-pathname</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0887" seq="1999-0887">
<status>Entry</status>
<desc>FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991104 FTGate Version 2.1 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1137">1137</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0888" seq="1999-0888">
<status>Entry</status>
<desc>dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.</desc>
<refs>
<ref source="BUGTRAQ">19990817 Security Bug in Oracle</ref>
<ref source="XF">oracle-dbsnmp</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/585">585</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0889" seq="1999-0889">
<status>Entry</status>
<desc>Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.</desc>
<refs>
<ref source="BUGTRAQ">19990810 Cisco 675 password nonsense</ref>
<ref source="XF">cisco-cbos-telnet</ref>
<ref source="OSVDB" url="http://www.osvdb.org/39">39</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0890" seq="1999-0890">
<status>Entry</status>
<desc>iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.</desc>
<refs>
<ref source="BUGTRAQ">19990928 Team Asylum: iHTML Merchant Vulnerabilities</ref>
<ref source="CONFIRM" url="http://www.ihtmlmerchant.com/support_patches_feedback.htm">http://www.ihtmlmerchant.com/support_patches_feedback.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/694">694</ref>
<ref source="XF">ihtml-merchant-file-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0891" seq="1999-0891">
<status>Entry</status>
<desc>The &quot;download behavior&quot; in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-040.mspx">MS99-040</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242542">Q242542</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/37828">VU#37828</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-002.shtml">K-002</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/674">674</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11274">11274</ref>
<ref source="XF">ie-download-behavior</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0892" seq="1999-0892">
<status>Entry</status>
<desc>Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.</desc>
<refs>
<ref source="BUGTRAQ">19991018 Netscape 4.x buffer overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0893" seq="1999-0893">
<status>Entry</status>
<desc>userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991011 SCO OpenServer 5.0.5 overwrite /etc/shadow</ref>
<ref source="XF">sco-openserver-userosa-script</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0894" seq="1999-0894">
<status>Entry</status>
<desc>Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.</desc>
<refs>
<ref source="REDHAT">RHSA1999042-01</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0895" seq="1999-0895">
<status>Entry</status>
<desc>Firewall-1 does not properly restrict access to LDAP attributes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991020150002.21047.qmail@tarjan.mediaways.net">19991020 Checkpoint FireWall-1 V4.0: possible bug in LDAP authentication</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/725">725</ref>
<ref source="XF">checkpoint-ldap-auth</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1117">1117</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0896" seq="1999-0896">
<status>Entry</status>
<desc>Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.</desc>
<refs>
<ref source="BUGTRAQ">19991109 RealNetworks RealServer G2 buffer overflow.</ref>
<ref source="MISC" url="http://service.real.com/help/faq/servg260.html">http://service.real.com/help/faq/servg260.html</ref>
<ref source="XF">realserver-g2-pw-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/767">767</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0897" seq="1999-0897">
<status>Entry</status>
<desc>iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90538488231977&amp;w=2">19980908 bug in iChat 3.0 (maybe others)</ref>
<ref source="XF">ichat-file-read-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0898" seq="1999-0898">
<status>Entry</status>
<desc>Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx">MS99-047</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649">Q243649</ref>
<ref source="XF">nt-printer-spooler-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/768">768</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0899" seq="1999-0899">
<status>Entry</status>
<desc>The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx">MS99-047</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649">Q243649</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/769">769</ref>
<ref source="XF">nt-printer-spooler-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0900" seq="1999-0900">
<status>Entry</status>
<desc>Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0901" seq="1999-0901">
<status>Entry</status>
<desc>ypserv allows a local user to modify the GECOS and login shells of other users.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0902" seq="1999-0902">
<status>Entry</status>
<desc>ypserv allows local administrators to modify password tables.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0903" seq="1999-0903">
<status>Entry</status>
<desc>genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.</desc>
<refs>
<ref source="BUGTRAQ">19991025 IBM AIX Packet Filter module</ref>
<ref source="BUGTRAQ">19991027 Re: IBM AIX Packet Filter module (followup)</ref>
<ref source="XF">aix-genfilt-filtering</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0904" seq="1999-0904">
<status>Entry</status>
<desc>Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.</desc>
<refs>
<ref source="BUGTRAQ">19991103 Remote DoS Attack in BFTelnet Server v1.1 for Windows NT</ref>
<ref source="XF">bftelnet-username-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/771">771</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0905" seq="1999-0905">
<status>Entry</status>
<desc>Denial of service in Axent Raptor firewall via malformed zero-length IP options.</desc>
<refs>
<ref source="BUGTRAQ">19991020 Remote DoS in Axent's Raptor 6.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/736">736</ref>
<ref source="XF">raptor-ipoptions-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1121">1121</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0906" seq="1999-0906">
<status>Entry</status>
<desc>Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990923 SuSE 6.2 sccw overflow exploit</ref>
<ref source="SUSE">19990926 Security hole in sccw (Part II)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/656">656</ref>
<ref source="XF">linux-sccw-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0907" seq="1999-0907">
<status>Entry</status>
<desc>sccw allows local users to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">19990916 SuSE 6.2 /usr/bin/sccw read any file</ref>
<ref source="SUSE">19990921 Security Hole in sccw-1.1 and earlier</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0908" seq="1999-0908">
<status>Entry</status>
<desc>Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.</desc>
<refs>
<ref source="BUGTRAQ">19990921 solaris DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/655">655</ref>
<ref source="XF">sun-tcp-mutex-enter-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0909" seq="1999-0909">
<status>Entry</status>
<desc>Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the &quot;Spoofed Route Pointer&quot; vulnerability.</desc>
<refs>
<ref source="NAI">Windows IP Source Routing Vulnerability</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-038.mspx">MS99-038</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238453">Q238453</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/646">646</ref>
<ref source="XF">nt-ip-source-route</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0910" seq="1999-0910">
<status>Candidate</status>
<phase date="19991208">Proposed</phase>
<desc>Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-035.asp">MS99-035</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/625">625</ref>
</refs>
<votes>
<accept count="4">Baker, Ozancin, Prosser, Wall</accept>
<modify count="2">Frech, Stracener</modify>
<reject count="1">Cole</reject>
</votes>
<comments>
<comment voter="Frech">XF:siteserver-cis-cookie-cache</comment>
<comment voter="Cole">Whether cookies are a vulnerbality is a debate for another time, the
question here is whether the
expiration feature is a vulnerability and I do not think it is
because the underlying concerns for this
are present even without this feature.  The expiration feature does
not add any new vulenrabilities
that are not already present with cookies.</comment>
<comment voter="Stracener">Add Ref: MSKB Q238647</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0911" seq="1999-0911">
<status>Candidate</status>
<phase date="20050309">Modified</phase>
<desc>Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.</desc>
<refs>
<ref source="BUGTRAQ">19990827 ProFTPD</ref>
<ref source="BUGTRAQ">19990907 ProFTP-1.2.0pre4 buffer overflow -- once more</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/1999/19990210">19990210</ref>
<ref source="FREEBSD">FreeBSD-SA-99:03</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/612">612</ref>
</refs>
<votes>
<accept count="5">Baker, Blake, Cole, Prosser, Stracener</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:proftpd-long-dir-bo(3399)</comment>
<comment voter="Christey">Not absolutely sure if this isn't the same as Palmetto
(CVE-1999-0368), which describes a similar type of overflow.

NETBSD:NetBSD-SA1999-003 may refer to CVE-1999-0368:
ADDREF URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-003.txt.asc</comment>
<comment voter="Christey">ADDREF CIAC:J-068
Include version numbers; too many wu-ftp/etc. problems
were published in summer/fall 1999</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0912" seq="1999-0912">
<status>Entry</status>
<desc>FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.</desc>
<refs>
<ref source="BUGTRAQ">19990921 FreeBSD-specific denial of service</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/653">653</ref>
<ref source="XF">freebsd-vfscache-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1079">1079</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0913" seq="1999-0913">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93383593909438&amp;w=2">19990804 NSW Dragon Fire gets drowned</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/564">564</ref>
</refs>
<votes>
<accept count="2">Blake, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="4">Armstrong, Baker, Cole, LeBlanc</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">Some voters should use ABSTAIN.  </comment>
<comment voter="Frech">XF:dragon-fire-ids-metachar(3834)</comment>
<comment voter="CHANGE">[Armstrong changed vote from REVIEWING to NOOP]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0914" seq="1999-0914">
<status>Entry</status>
<desc>Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.</desc>
<refs>
<ref source="DEBIAN">19990104</ref>
<ref source="BUGTRAQ">19990103 [SECURITY] New versions of netstd fixes buffer overflows</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/324">324</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0915" seq="1999-0915">
<status>Entry</status>
<desc>URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991028 URL Live! 1.0 WebServer</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/746">746</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1129">1129</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0916" seq="1999-0916">
<status>Entry</status>
<desc>WebTrends software stores account names and passwords in a file which does not have restricted access permissions.</desc>
<refs>
<ref source="ISS">19990629 Bad Permissions on Passwords Stored by WebTrends Software</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0917" seq="1999-0917">
<status>Entry</status>
<desc>The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx">MS99-018</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231452">Q231452</ref>
<ref source="XF">legacy-activex-local-drive</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0918" seq="1999-0918">
<status>Entry</status>
<desc>Denial of service in various Windows systems via malformed, fragmented IGMP packets.</desc>
<refs>
<ref source="BUGTRAQ">19990703 IGMP fragmentation bug in Windows 98/2000</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238329">Q238329</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-034.mspx">MS99-034</ref>
<ref source="XF">igmp-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/514">514</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0919" seq="1999-0919">
<status>Candidate</status>
<phase date="20020226">Modified</phase>
<desc>A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9805B&amp;L=bugtraq&amp;P=R1621">19980510 Security Vulnerability in Motorola CableRouters</ref>
<ref source="XF" url="http://xforce.iss.net/static/2004.php">motorola-cable-crash(2004)</ref>
</refs>
<votes>
<accept count="2">Baker, Cole</accept>
<modify count="1">Frech</modify>
<noop count="7">Armstrong, Christey, Landfield, LeBlanc, Ozancin, Stracener, Wall</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Christey">This candidate is unconfirmed by the vendor.</comment>
<comment voter="Frech">XF:motorola-cable-crash</comment>
<comment voter="Christey">This has enough votes, but not the &quot;confidence&quot; yet (until we
resolve the question of the amount of verification needed
for CVE).</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0920" seq="1999-0920">
<status>Entry</status>
<desc>Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.</desc>
<refs>
<ref source="BUGTRAQ">19990526 Remote vulnerability in pop2d</ref>
<ref source="DEBIAN">19990607a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/283">283</ref>
<ref source="XF">pop2-fold-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0921" seq="1999-0921">
<status>Entry</status>
<desc>BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4291.php">bmc-patrol-udp-dos(4291)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1879">1879</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0922" seq="1999-0922">
<status>Entry</status>
<desc>An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref>
<ref source="XF">coldfusion-sourcewindow</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0923" seq="1999-0923">
<status>Candidate</status>
<phase date="20010214">Proposed</phase>
<desc>Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref>
</refs>
<votes>
<accept count="2">Baker, Cole</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:coldfusion-source-display(1741)
XF:coldfusion-syntax-checker(1742)
XF:coldfusion-file-existence(1743)
XF:coldfusion-sourcewindow(1744)</comment>
<comment voter="Christey">List all affected runnable code snippets to facilitate
search, which may include:
viewexample.cfm (though could that be part of CVE-1999-0922?)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0924" seq="1999-0924">
<status>Entry</status>
<desc>The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1742">coldfusion-syntax-checker(1742)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3236">3236</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0925" seq="1999-0925">
<status>Candidate</status>
<phase date="20020829">Modified</phase>
<desc>UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90486243124867&amp;w=2">19980903 Web servers / possible DOS Attack / mime header flooding</ref>
</refs>
<votes>
<accept count="2">Baker, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:unitymail-web-dos(1630)</comment>
<comment voter="Christey">BID:1760
URL:http://www.securityfocus.com/bid/1760</comment>
<comment voter="Christey">Affected version is 2.0
Change date of Bugtraq post - it was 1998.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0926" seq="1999-0926">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html">19990903 Web servers / possible DOS Attack / mime header flooding</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Christey">BID:1760
URL:http://www.securityfocus.com/bid/1760</comment>
<comment voter="Frech">XF:unitymail-web-dos(1630)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0927" seq="1999-0927">
<status>Entry</status>
<desc>NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/279">279</ref>
<ref source="XF">ntmail-fileread</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0928" seq="1999-0928">
<status>Entry</status>
<desc>Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ">19990525 Buffer overflow in SmartDesk WebSuite v2.1</ref>
<ref source="XF">websuite-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/278">278</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0929" seq="1999-0929">
<status>Candidate</status>
<phase date="19991229">Interim</phase>
<desc>Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.</desc>
<refs>
<ref source="BUGTRAQ">19990616 Novell NetWare webservers DoS</ref>
</refs>
<votes>
<accept count="4">Armstrong, Blake, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
</votes>
<comments>
<comment voter="Frech">XF:novell-webserver-dos(2287)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0930" seq="1999-0930">
<status>Entry</status>
<desc>wwwboard allows a remote attacker to delete message board articles via a malformed argument.</desc>
<refs>
<ref source="BUGTRAQ">19980903 wwwboard.pl vulnerability</ref>
<ref source="CONFIRM" url="http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml">http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml</ref>
<ref source="XF" url="http://xforce.iss.net/static/2344.php">http-cgi-wwwboard(2344)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1795">1795</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0931" seq="1999-0931">
<status>Entry</status>
<desc>Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19990930 Security flaw in Mediahouse Statistics Server v4.28 &amp; 5.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/734">734</ref>
<ref source="XF">mediahouse-stats-login-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0932" seq="1999-0932">
<status>Entry</status>
<desc>Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.</desc>
<refs>
<ref source="BUGTRAQ">19990930 Security flaw in Mediahouse Statistics Server v4.28 &amp; 5.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/735">735</ref>
<ref source="XF">mediahouse-stats-adminpw-cleartext</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0933" seq="1999-0933">
<status>Entry</status>
<desc>TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991001 RFP9904: TeamTrack webserver vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/689">689</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1096">1096</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0934" seq="1999-0934">
<status>Entry</status>
<desc>classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.</desc>
<refs>
<ref source="EL8">19991215 Classifieds (classifieds.cgi)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2020">2020</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3102">http-cgi-classifieds-read(3102)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0935" seq="1999-0935">
<status>Entry</status>
<desc>classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.</desc>
<refs>
<ref source="EL8">19991215 Classifieds (classifieds.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0936" seq="1999-0936">
<status>Entry</status>
<desc>BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="EL8">19981203 BNBSurvey (survey.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0937" seq="1999-0937">
<status>Entry</status>
<desc>BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.</desc>
<refs>
<ref source="EL8">19981203 BNBForm (bnbform.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0938" seq="1999-0938">
<status>Entry</status>
<desc>MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Sesion Initiation Protocol (SIP) messages.</desc>
<refs>
<ref source="CERT">VN-99-03</ref>
<ref source="XF">sdr-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0939" seq="1999-0939">
<status>Entry</status>
<desc>Denial of service in Debian IRC Epic/epic4 client via a long string.</desc>
<refs>
<ref source="BUGTRAQ">19990826 [SECURITY] New versions of epic4 fixes possible DoS vulnerability</ref>
<ref source="DEBIAN">19990826</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/605">605</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0940" seq="1999-0940">
<status>Entry</status>
<desc>Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.</desc>
<refs>
<ref source="CALDERA">CSSA-1999-031</ref>
<ref source="SUSE">19990927 Security hole in mutt</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0941" seq="1999-0941">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Mutt mail client allows a remote attacker to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526154&amp;w=2">19980728 mutt x.x</ref>
</refs>
<votes>
<accept count="1">Stracener</accept>
<noop count="2">Baker, Christey</noop>
<reject count="1">Frech</reject>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">References are vague, but seem to be identical to CVE-1999-0940
(XF:mutt-text-enriched-mime-bo). According to the references, the malformed
messages consist of metacharacters. In addition, -0941's reference and
-0940's SuSE reference both refer to fixes in 1.0pre3 release. Will
reconsider vote if other clearer references are forthcoming.</comment>
<comment voter="Christey">Modify to mention that the metachar's are in the Content-Type header.
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526154&amp;w=2</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0942" seq="1999-0942">
<status>Entry</status>
<desc>UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.</desc>
<refs>
<ref source="BUGTRAQ">19991005 SCO UnixWare 7.1 local root exploit</ref>
<ref source="XF">sco-unixware-dos7utils-root-privs</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0943" seq="1999-0943">
<status>Entry</status>
<desc>Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.</desc>
<refs>
<ref source="BUGTRAQ">19991015 OpenLink 3.2 Advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/720">720</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0944" seq="1999-0944">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.</desc>
<refs>
<ref source="BUGTRAQ">19991024 password leak in IBM WebSphere / HTTP Server / ikeyman</ref>
</refs>
<votes>
<accept count="2">Baker, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Bollinger, Christey</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:websphere-database-pwd-accessible</comment>
<comment voter="Christey">ADDREF BID:1763
URL:http://www.securityfocus.com/bid/1763</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0945" seq="1999-0945">
<status>Entry</status>
<desc>Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise4.php">19980724 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-080.shtml">I-080</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q169174">Q169174</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1223">exchange-dos(1223)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0946" seq="1999-0946">
<status>Entry</status>
<desc>Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="XF">yamaha-midiplug-embed</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/760">760</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0947" seq="1999-0947">
<status>Entry</status>
<desc>AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/762">762</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0948" seq="1999-0948">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Buffer overflow in uum program for Canna input system allows local users to gain root privileges.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/757">757</ref>
<ref source="BUGTRAQ">19991102 Some holes for Win/UNIX softwares</ref>
</refs>
<votes>
<accept count="2">Levy, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
</votes>
<comments>
<comment voter="Christey">CVE-1999-0948 and CVE-1999-0949 are extremely similar.
uum (0948) is exploitable through a different set of options
than canuum (0949).  If it's the same generic option parsing
routine used by both programs, then CD:SF-CODEBASE says to
merge them.  But if it's not, then CD:SF-LOC and CD:SF-EXEC
says to split them.  However, this is a prime example of
how SF-EXEC might be modified - uum and canuum are clearly
part of the same package, so in the absence of clear
information, maybe we should merge them.</comment>
<comment voter="Frech">XF:canna-uum-bo</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0949" seq="1999-0949">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/757">757</ref>
<ref source="BUGTRAQ">19991102 Some holes for Win/UNIX softwares</ref>
</refs>
<votes>
<accept count="2">Levy, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Christey</noop>
</votes>
<comments>
<comment voter="Christey">CVE-1999-0948 and CVE-1999-0949 are extremely similar.
uum (0948) is exploitable through a different set of options
than canuum (0949).  If it's the same generic option parsing
routine used by both programs, then CD:SF-CODEBASE says to
merge them.  But if it's not, then CD:SF-LOC and CD:SF-EXEC
says to split them.  However, this is a prime example of
how SF-EXEC might be modified - uum and canuum are clearly
part of the same package, so in the absence of clear
information, maybe we should merge them.

Also review BID:758 and BID:757 - may need to change the BID
here.</comment>
<comment voter="Frech">XF:canna-uum-bo</comment>
<comment voter="Christey">CHANGEREF BID:757 BID:758</comment>
<comment voter="Christey">The following page says that canuum is a &quot;Japanese input tty
frontend for Canna using uum,&quot; which suggests that it is, at
the least, a different package, so perhaps this should stay SPLIT.

http://wuarchive.wustl.edu/mirrors/NetBSD/NetBSD-current/pkgsrc/inputmethod/canuum/README.html</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0950" seq="1999-0950">
<status>Entry</status>
<desc>Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via	a series of MKD and CWD commands that create nested directories.</desc>
<refs>
<ref source="BUGTRAQ">19991027 WFTPD v2.40 FTPServer remotely exploitable buffer overflow vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/747">747</ref>
<ref source="XF">wftpd-mkd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0951" seq="1999-0951">
<status>Entry</status>
<desc>Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19991022 Imagemap CGI overflow exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/739">739</ref>
<ref source="XF">http-cgi-imagemap-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3380">3380</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0952" seq="1999-0952">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91759216618637&amp;w=2">19990126 Buffer overflow in Solaris 2.6/2.7 /usr/bin/lpstat</ref>
</refs>
<votes>
<accept count="3">Baker, Ozancin, Stracener</accept>
<modify count="2">Dik, Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:solaris-lpstat-bo</comment>
<comment voter="Christey">It is unclear from Casper Dik's followup whether this is
exploitable or not.</comment>
<comment voter="Dik">Sunbug 4129917
(other reports in the same thread suggest that the then current patchd id
fix the problem)</comment>
<comment voter="Christey">Confirm with Casper Dik that the overflow is in the -c option,
and if so, include it in the description to differentiate
it from the lpstat -n buffer overflow.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0953" seq="1999-0953">
<status>Entry</status>
<desc>WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.</desc>
<refs>
<ref source="BUGTRAQ">19980903 wwwboard.pl vulnerability</ref>
<ref source="BUGTRAQ">19990916 More fun with WWWBoard</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0954" seq="1999-0954">
<status>Entry</status>
<desc>WWWBoard has a default username and default password.</desc>
<refs>
<ref source="BUGTRAQ">19990916 More fun with WWWBoard</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/649">649</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0955" seq="1999-0955">
<status>Entry</status>
<desc>Race condition in wu-ftpd and BSDI ftpd allows remote attackers gain root access via the SITE EXEC command.</desc>
<refs>
<ref source="CERT">CA-94.08</ref>
<ref source="CIAC">E-17</ref>
<ref source="XF">ftp-exec</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0956" seq="1999-0956">
<status>Entry</status>
<desc>The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.</desc>
<refs>
<ref source="CERT">CA-93.02a</ref>
<ref source="XF">next-netinfo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0957" seq="1999-0957">
<status>Entry</status>
<desc>MajorCool mj_key_cache program allows local users to modify files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19970618 Security hole in MajorCool 1.0.3</ref>
<ref source="XF">majorcool-file-overwrite-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0958" seq="1999-0958">
<status>Entry</status>
<desc>sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88465708614896&amp;w=2">19980112 Re: hole in sudo for MP-RAS.</ref>
<ref source="XF">sudo-dot-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0959" seq="1999-0959">
<status>Entry</status>
<desc>IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19970209 IRIX: Bug in startmidi</ref>
<ref source="AUSCERT">AA-97-05</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/469">469</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8447">8447</ref>
<ref source="XF">irix-startmidi-file-creation((1634)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0960" seq="1999-0960">
<status>Entry</status>
<desc>IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.</desc>
<refs>
<ref source="AUSCERT">AA-96.11</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
<ref source="XF">irix-cdplayer-directory-create</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0961" seq="1999-0961">
<status>Entry</status>
<desc>HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419906&amp;w=2">19960921 Vunerability in HP sysdiag ?</ref>
<ref source="CIAC">H-03</ref>
<ref source="XF">hp-sysdiag-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0962" seq="1999-0962">
<status>Entry</status>
<desc>Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.</desc>
<refs>
<ref source="AUSCERT">AA-96.13</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9701-045">HPSBUX9701-045</ref>
<ref source="XF">hp-password-cmd-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6415">6415</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0963" seq="1999-0963">
<status>Entry</status>
<desc>FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19960517 BoS: SECURITY BUG in FreeBSD</ref>
<ref source="CERT">VB-96.06</ref>
<ref source="XF">freebsd-mount-union-root</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6088">6088</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0964" seq="1999-0964">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-97:01</ref>
<ref source="XF">freebsd-setlocale-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6086">6086</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0965" seq="1999-0965">
<status>Entry</status>
<desc>Race condition in xterm allows local users to modify arbitrary files via the logging option.</desc>
<refs>
<ref source="CERT">CA-93.17</ref>
<ref source="XF">xterm</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0966" seq="1999-0966">
<status>Entry</status>
<desc>Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].</desc>
<refs>
<ref source="L0PHT">19970127 Solaris libc - getopt(3)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0967" seq="1999-0967">
<status>Entry</status>
<desc>Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.</desc>
<refs>
<ref source="L0PHT">19971101 Microsoft Internet Explorer 4.0 Suite</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0968" seq="1999-0968">
<status>Entry</status>
<desc>Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11711">19981226 bnc exploit</ref>
<ref source="XF" url="http://xforce.iss.net/static/1546.php">bnc-proxy-bo(1546)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1927">1927</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0969" seq="1999-0969">
<status>Entry</status>
<desc>The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.</desc>
<refs>
<ref source="ISS">19980929 &quot;Snork&quot; Denial of Service Attack Against Windows NT RPC Service</ref>
<ref source="NTBUGTRAQ">19980929 ISS Security Advisory: Snork</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-014.mspx">MS98-014</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q193233">Q193233</ref>
<ref source="XF">snork-dos</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0970" seq="1999-0970">
<status>Candidate</status>
<phase date="20020226">Modified</phase>
<desc>The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14311">19990605 Remote Exploit (Bug) in OmniHTTPd Web Server</ref>
<ref source="XF" url="http://xforce.iss.net/static/2271.php">omnihttpd-dos(2271)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1808">1808</ref>
</refs>
<votes>
<accept count="3">Baker, Blake, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:omnihttpd-dos</comment>
<comment voter="Christey">Some sort of confirmation might be findable at:
http://www.omnicron.ab.ca/httpd/docs/release.html</comment>
<comment voter="Christey">See http://www.omnicron.ab.ca/index.html
The August 16, 2000 news item says &quot;This release fixes some
security problems.&quot;  It's for version 2.07, but the discloser
didn't say what version was available.

Other security fixes are in the release notes at
http://www.omnicron.ab.ca/httpd/docs/release.html Notes for
Professional Version 1.01 say &quot;Patched up two security weaknesses.&quot;
Notes for version 2.07 say &quot;Fixes dot-appending vulnerability.&quot;
Professional Alpha 7 says &quot;Revamped CGI launching and security,&quot;
Professional Alpha 4 says &quot;Fixed SSI path mapping and security
problems,&quot; Alpha 5 says &quot;Security fixup.&quot;

In other words, you can't tell whether they've fixed this bug
or not.</comment>
<comment voter="Christey">BID:1808
URL:http://www.securityfocus.com/bid/1808</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0971" seq="1999-0971">
<status>Entry</status>
<desc>Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7301">19970722 Security hole in exim 1.62: local root exploit</ref>
<ref source="XF">exim-include-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0972" seq="1999-0972">
<status>Entry</status>
<desc>Buffer overflow in Xshipwars xsw program.</desc>
<refs>
<ref source="BUGTRAQ">19991209 xsw 1.24 remote buffer overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/863">863</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0973" seq="1999-0973">
<status>Entry</status>
<desc>Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.</desc>
<refs>
<ref source="BUGTRAQ">19991206 [w00giving #8] Solaris 2.7's snoop</ref>
<ref source="BUGTRAQ">19991209 Clarification needed on the snoop vuln(s) (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/858">858</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0974" seq="1999-0974">
<status>Entry</status>
<desc>Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.</desc>
<refs>
<ref source="ISS">19991209 Buffer Overflow in Solaris Snoop</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/190">00190</ref>
<ref source="BUGTRAQ">19991209 Clarification needed on the snoop vuln(s) (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/864">864</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0975" seq="1999-0975">
<status>Entry</status>
<desc>The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.</desc>
<refs>
<ref source="BUGTRAQ">19991207 Local user can fool another to run executable. .CNT/.GID/.HLP M$WINNT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/868">868</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0976" seq="1999-0976">
<status>Entry</status>
<desc>Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.</desc>
<refs>
<ref source="OPENBSD">19991204</ref>
<ref source="BUGTRAQ">19991207 [Debian] New version of sendmail released</ref>
<ref source="XF">sendmail-bi-alias</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/857">857</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0977" seq="1999-0977">
<status>Entry</status>
<desc>Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.</desc>
<refs>
<ref source="SF-INCIDENTS">19991209 sadmind</ref>
<ref source="BUGTRAQ">19991210 Solaris sadmind Buffer Overflow Vulnerability</ref>
<ref source="BUGTRAQ">19991210 Re: Solaris sadmind Buffer Overflow Vulnerability</ref>
<ref source="CERT">CA-99-16</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/191">00191</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/866">866</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2354">2354</ref>
<ref source="XF">sol-sadmind-amslverify-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2558">2558</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0978" seq="1999-0978">
<status>Entry</status>
<desc>htdig allows remote attackers to execute commands via filenames with shell metacharacters.</desc>
<refs>
<ref source="DEBIAN">19991209</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/867">867</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0979" seq="1999-0979">
<status>Entry</status>
<desc>The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Fundamental flaw in UnixWare 7 security</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/869">869</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0980" seq="1999-0980">
<status>Entry</status>
<desc>Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-055.mspx">MS99-055</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246045">Q246045</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0981" seq="1999-0981">
<status>Entry</status>
<desc>Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka &quot;Server-side Page Reference Redirect.&quot;</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-050.mspx">MS99-050</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246094">Q246094</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0982" seq="1999-0982">
<status>Entry</status>
<desc>The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.</desc>
<refs>
<ref source="BUGTRAQ">19991206 Solaris WBEM 1.0: plaintext password stored in world readable file</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0983" seq="1999-0983">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</desc>
<refs>
<ref source="BUGTRAQ">19991109 Whois.cgi - ADVISORY.</ref>
</refs>
<votes>
<accept count="3">Blake, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">More examination is required to determine if CVE-1999-0983,
CVE-1999-0984, or CVE-1999-0985 are the same codebase.</comment>
<comment voter="Frech">XF:whois-internic-shell-meta</comment>
<comment voter="Christey">ADDREF BID:2000</comment>
<comment voter="Christey">The XF appears to be gone.  Perhaps it's this one:
XF:http-cgi-whois-meta(3798)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0984" seq="1999-0984">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</desc>
<refs>
<ref source="BUGTRAQ">19991109 Whois.cgi - ADVISORY.</ref>
</refs>
<votes>
<accept count="2">Blake, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Cole</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Cole">How is this different than the previous?</comment>
<comment voter="Christey">More examination is required to determine if CVE-1999-0983,
CVE-1999-0984, or CVE-1999-0985 are the same codebase.</comment>
<comment voter="Frech">XF:matts-whois-meta</comment>
<comment voter="Christey">ADDREF BID:2000</comment>
<comment voter="Christey">XF reference is gone.  Replace with http-cgi-matts-whois-meta(3799) ?</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0985" seq="1999-0985">
<status>Candidate</status>
<phase date="19991214">Proposed</phase>
<desc>CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</desc>
<refs>
<ref source="BUGTRAQ">19991109 Whois.cgi - ADVISORY.</ref>
</refs>
<votes>
<accept count="2">Blake, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Cole</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Cole">I would combine all of these.</comment>
<comment voter="Christey">More examination is required to determine if CVE-1999-0983,
CVE-1999-0984, or CVE-1999-0985 are the same codebase.</comment>
<comment voter="Frech">XF:cc-whois-meta</comment>
<comment voter="Christey">ADDREF BID:2000</comment>
<comment voter="Frech">Change cc-whois-meta(3800) to http-cgi-ccwhois(3747)</comment>
<comment voter="Christey">Replace XF reference with XF:cc-whois-meta(3800) ?</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0986" seq="1999-0986">
<status>Entry</status>
<desc>The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Big problem on 2.0.x?</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/870">870</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0987" seq="1999-0987">
<status>Entry</status>
<desc>Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.</desc>
<refs>
<ref source="NTBUGTRAQ">19991118 NT System Policy for Win95 Not downloaded when adding a space after domain name</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237923">Q237923</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0988" seq="1999-0988">
<status>Candidate</status>
<phase date="20000121">Modified</phase>
<desc>UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991204 UnixWare pkg* command exploits</ref>
<ref source="BUGTRAQ">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BUGTRAQ">19991223 FYI, SCO Security patches available.</ref>
<ref source="BUGTRAQ">19991220 SCO OpenServer Security Status</ref>
</refs>
<votes>
<accept count="3">Baker, Blake, Cole</accept>
<modify count="1">Frech</modify>
<recast count="1">Stracener</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Stracener">The pkg* programs pkgtrans, pkginfo, pkgcat, pkginstall, and pkgparam
can be used to mount etc/shadow printing attacks as a result of the
&quot;dacread&quot; permission (cf. /etc/security/tcb/privs). The procedural
differences between the individual exploits for each of these utilities
are therefore inconsequential. CVE-1999-0988 should be merged with
CVE-1999-0828. From the standpoint of maintaining consistency of the
level of abstraction used in CVE, the co-existence of CANS
1999-0988/1999-0828 present two choices: either merge 0988 with 0828, or
split 0828 into 4 distinct candidates, keeping 0988 intact. Due to the
very small differences (in principle) between the exploits subsumed by
0828 and 0988 and the shared dacread permissions of the pkg* suite, I
suggest a merge. Below is a summary of the data upon which my decision
was based.
utility         exploit
--------      ---------------------------------- </comment>
<comment voter="pkgtrans  --">symlink + dacread permission prob</comment>
<comment voter="pkginfo   --">truss (debugging utility) in conjunction with pkginfio -d
etc/shadow. In this case, it captures the interaction between
pkginfo                the shadow file. Once again: dacread.</comment>
<comment voter="pkgcat    --">buffer overflow  + dacread permission prob</comment>
<comment voter="pkginstall -">buffer overflow + dacread permission prob</comment>
<comment voter="pkgparam --">-f etc/shadow (works because of dacread).</comment>
<comment voter="Christey">This is a tough one.  While there are few procedural
differences, one could view &quot;assignment of an improper
permission&quot; as a &quot;class&quot; of problems along the lines of
buffer overflows and the like.  Just like some programs
were fine until they got turned into CGI scripts, this
could be an emerging pattern which should be given
consideration.  Consider the Eyedog and scriptlet.typelib
ActiveX utilities being marked as safe for scripting
(CVE-1999-0668 and 0669).

ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a loosely
alludes to this problem; the README for patch SSE053
effectively confirms it.</comment>
<comment voter="Frech">XF:unixware-pkgtrans-symlink</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0989" seq="1999-0989">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.</desc>
<refs>
<ref source="NTBUGTRAQ">19991205 new IE5 remote exploit</ref>
<ref source="BUGTRAQ">19991205 new IE5 remote exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/861">861</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0990" seq="1999-0990">
<status>Candidate</status>
<phase date="19991229">Interim</phase>
<desc>Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.</desc>
<refs>
<ref source="BUGTRAQ">19991205 gdm thing</ref>
</refs>
<votes>
<accept count="3">Blake, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
</votes>
<comments>
<comment voter="Frech">XF:verbose-auth-identify-user(3804)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0991" seq="1999-0991">
<status>Entry</status>
<desc>Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.</desc>
<refs>
<ref source="NTBUGTRAQ">19991206 Remote DoS Attack in GoodTech Telnet Server NT v2.2.1 Vulnerability</ref>
<ref source="BUGTRAQ">19991206 Remote DoS Attack in GoodTech Telnet Server NT v2.2.1 Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/862">862</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0992" seq="1999-0992">
<status>Entry</status>
<desc>HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9912-107">HPSBUX9912-107</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0993" seq="1999-0993">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Modifications to ACLs (Access Control Lists) in Microsoft Exchange  5.5 do not take effect until the directory store cache is refreshed.</desc>
<refs>
<ref source="NTBUGTRAQ">19991213 Changing ACL's in Exchange Server</ref>
</refs>
<votes>
<accept count="2">Stracener, Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Baker, Cole</noop>
<reject count="1">LeBlanc</reject>
</votes>
<comments>
<comment voter="Frech">XF:exchange-acl-changes(3916)</comment>
<comment voter="LeBlanc">Not a vulnerability</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0994" seq="1999-0994">
<status>Entry</status>
<desc>Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.</desc>
<refs>
<ref source="BINDVIEW">19991216 Windows NT's SYSKEY feature</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-056.mspx">MS99-056</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248183">Q248183</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/873">873</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0995" seq="1999-0995">
<status>Entry</status>
<desc>Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka &quot;Malformed Security Identifier Request.&quot;</desc>
<refs>
<ref source="NAI">19991216 Windows NT LSA Remote Denial of Service</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-057.mspx">MS99-057</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248185">Q248185</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/875">875</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0996" seq="1999-0996">
<status>Entry</status>
<desc>Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD19991215.html">AD19991215</ref>
<ref source="BUGTRAQ">19991216 Infoseek Ultraseek Remote Buffer Overflow</ref>
<ref source="NTBUGTRAQ">19991216 Infoseek Ultraseek Remote Buffer Overflow</ref>
<ref source="XF">infoseek-ultraseek-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6490">6490</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0997" seq="1999-0997">
<status>Entry</status>
<desc>wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.</desc>
<refs>
<ref source="BUGTRAQ">19991220 Security vulnerability in certain wu-ftpd (and derivitives) configurations (fwd)</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-377">DSA-377</ref>
<ref source="XF">wuftp-ftp-conversion</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0998" seq="1999-0998">
<status>Entry</status>
<desc>Cisco Cache Engine allows an attacker to replace content in the cache.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="XF">cisco-cache-engine-replace</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0999" seq="1999-0999">
<status>Entry</status>
<desc>Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-059.mspx">MS99-059</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248749">Q248749</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/817">817</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1000" seq="1999-1000">
<status>Entry</status>
<desc>The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="XF">cisco-cache-engine-performance</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1001" seq="1999-1001">
<status>Entry</status>
<desc>Cisco Cache Engine allows a remote attacker to gain access via a null username and password.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1002" seq="1999-1002">
<status>Candidate</status>
<phase date="20030619">Modified</phase>
<desc>Netscape Navigator uses weak encryption for storing a user's Netscape mail password.</desc>
<refs>
<ref source="MISC" url="http://www.rstcorp.com/news/bad-crypto.html">http://www.rstcorp.com/news/bad-crypto.html</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94536309217214&amp;w=2">19991216 Reinventing the wheel (aka &quot;Decoding Netscape Mail passwords&quot;)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94570673523998&amp;w=2">19991220 Netscape password scrambling</ref>
</refs>
<votes>
<accept count="4">Baker, Cole, Stracener, Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">XF:netscape-mail-encryption(3921)</comment>
<comment voter="Christey">CHANGEREF make the RCA URL a &quot;MISC&quot; reference</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1003" seq="1999-1003">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.</desc>
<refs>
<ref source="BUGTRAQ">19991214 Local / Remote D.o.S Attack in War FTP Daemon 1.70 Vulnerability</ref>
<ref source="BUGTRAQ">19991216 Statement: Local / Remote D.o.S Attack in War FTP Daemon 1.70</ref>
</refs>
<votes>
<accept count="3">Baker, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:warftp-connection-flood</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1004" seq="1999-1004">
<status>Entry</status>
<desc>Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/38970">19991217 NAV2000 Email Protection DoS</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39194">19991220 Norton Email Protection Remote Overflow (Addendum)</ref>
<ref source="CONFIRM" url="http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy">http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6267">6267</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1005" seq="1999-1005">
<status>Entry</status>
<desc>Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94571433731824&amp;w=2">19991219 Groupewise Web Interface</ref>
<ref source="XF">groupwise-web-read-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/879">879</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3413">3413</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1006" seq="1999-1006">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94571433731824&amp;w=2">19991219 Groupewise Web Interface</ref>
</refs>
<votes>
<accept count="4">Baker, Cole, Prosser, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:groupwise-web-path</comment>
<comment voter="Prosser">Pretty well confirmed by testing with responses to BugTraq list.

additional ref:  BugTraq ID 879  http://www.securityfocus.com/bid/879</comment>
<comment voter="Christey">A later discovery almost 2 years later is at:
BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell
GroupWise Web Access Path Disclosure Vulnerability
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=101494830315071&amp;w=2
CD:SF-LOC might suggest merging these together.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1007" seq="1999-1007">
<status>Entry</status>
<desc>Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94512259331599&amp;w=2">19991213 VDO Live Player 3.02 Buffer Overflow</ref>
<ref source="XF">vdolive-bo-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/872">872</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1008" seq="1999-1008">
<status>Entry</status>
<desc>xsoldier program allows local users to gain root access via a long argument.</desc>
<refs>
<ref source="BUGTRAQ">19991215 FreeBSD 3.3 xsoldier root exploit</ref>
<ref source="MISC" url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2">http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/871">871</ref>
<ref source="XF">unix-xsoldier-overflow</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1009" seq="1999-1009">
<status>Candidate</status>
<phase date="19991222">Proposed</phase>
<desc>The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.</desc>
<refs>
<ref source="BUGTRAQ">19991213 Privacy hole in Go Express Search</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="4">Balinsky, Cole, Stracener, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:disney-search-info(3955)</comment>
<comment voter="Balinsky">The go.express.com web site does not mention the existence of the Express web server mentioned in the advisory. There appears to be no way of verifying this.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1010" seq="1999-1010">
<status>Entry</status>
<desc>An SSH 1.2.27 server allows a client to use the &quot;none&quot; cipher, even if it is not allowed by the server policy.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94519142415338&amp;w=2">19991214 sshd1 allows unencrypted sessions regardless of server policy</ref>
<ref source="XF">ssh-policy-bypass</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1011" seq="1999-1011">
<status>Entry</status>
<desc>The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-004.asp">MS98-004</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-025.asp">MS99-025</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-054.shtml">J-054</ref>
<ref source="ISS">19990809 Vulnerabilities in Microsoft Remote Data Service</ref>
<ref source="BID" url="http://www.ciac.org/ciac/bulletins/j-054.shtml">529</ref>
<ref source="XF">nt-iis-rds</ref>
<ref source="OSVDB" url="http://www.osvdb.org/272">272</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1012" seq="1999-1012">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13527">19990504 AS/400</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/173">173</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">(Task 1770)</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:lotus-domino-smtp-dos(8790)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1013" seq="1999-1013">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/673">673</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837026726954&amp;w=2">19990923 named-xfer hole on AIX (fwd)</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:aix-named-xfer-root-access(3308)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1014" seq="1999-1014">
<status>Entry</status>
<desc>Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93727925026476&amp;w=2">19990913 Solaris 2.7 /usr/bin/mail</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93846422810162&amp;w=2">19990927 Working Solaris x86 /usr/bin/mail exploit</ref>
<ref source="SUNBUG">4276509</ref>
<ref source="XF" url="http://xforce.iss.net/static/3297.php">sun-usrbinmail-local-bo(3297)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/672">672</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1015" seq="1999-1015">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a long HELO command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89200657216213&amp;w=2">19980408 AppleShare IP Mail Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/61">61</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:smtp-helo-bo(886)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1016" seq="1999-1016">
<status>Candidate</status>
<phase date="20040811">Modified</phase>
<desc>Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93578772920970&amp;w=2">19990827 HTML code to crash IE5 and Outlook Express 5</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/606">606</ref>
</refs>
<votes>
<accept count="2">Cole, Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:ms-html-table-form-dos(3246)</comment>
<comment voter="Frech">XF:ms-html-table-form-dos(3246)</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1017" seq="1999-1017">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93316253431588&amp;w=2">19990728 Seattle Labs EMURL Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/544">544</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">(Task 2281)</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:emurl-attachment-execution(8794)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1018" seq="1999-1018">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93312523904591&amp;w=2">19990727 Linux 2.2.10 ipchains Advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/543">543</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:linux-ipchains-bypass-filter(6516)</comment>
<comment voter="Frech">XF:linux-ipchains-bypass-filter(6516)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1019" seq="1999-1019">
<status>Entry</status>
<desc>SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398713491&amp;w=2">19990623 Cabletron Spectrum security vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398513475&amp;w=2">19990624 Re: Cabletron Spectrum security vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/495">495</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1020" seq="1999-1020">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90613355902262&amp;w=2">19980918 NMRC Advisory - Default NDS Rights</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/484">484</ref>
<ref source="XF" url="http://xforce.iss.net/static/1364.php">novell-nds(1364)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1021" seq="1999-1021">
<status>Entry</status>
<desc>NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-15.html">CA-1992-15</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/117&amp;type=0&amp;nav=sec.sba">00117</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/47">47</ref>
<ref source="XF" url="http://xforce.iss.net/static/82.php">nfs-uid(82)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1022" seq="1999-1022">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/930">19941002 </ref>
<ref source="XF" url="http://xforce.iss.net/static/2111.php">sgi-serialports(2111)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/464">464</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Christey, Foat</noop>
</votes>
<comments>
<comment voter="Christey">Note: CVE-1999-1310 is a duplicate of this candidate.
CVE-1999-1310 will be REJECTed; this is the proper CAN to use.

CIAC:F-01
URL:http://ciac.llnl.gov/ciac/bulletins/f-01.shtml
SGI:19941001-01-P
URL:ftp://patches.sgi.com/support/free/security/advisories/19941001-01-P
MISC:http://www.netsys.com/firewalls/firewalls-9410/0019.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1023" seq="1999-1023">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the &quot;-e&quot; (expiration date) argument, which could allow users to login after their accounts have expired.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92904175406756&amp;w=2">19990610 Sun Useradd program expiration date bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/426">426</ref>
</refs>
<votes>
<accept count="1">Dik</accept>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Dik">sun bug: 4222400</comment>
<comment voter="Frech">XF:solaris-useradd-expired-accounts(8375)
CONFIRM:(2.6)110883-01, (2.6_x86) 110884-01, (7)110869-01,
(7_x86) 110870-01</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1024" seq="1999-1024">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92955903802773&amp;w=2">19990616 tcpdump 3.4  bug?</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92963447601748&amp;w=2">19990617 Re: tcpdump 3.4 bug?</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92989907627051&amp;w=2">19990620 Re: tcpdump 3.4 bug? (final)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/313">313</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:tcpdump-ipprint-dos(8373)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1025" seq="1999-1025">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90831127921062&amp;w=2">19981012 Annoying Solaris/CDE/NIS+ bug</ref>
<ref source="SUNBUG" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F106027&amp;zone_32=411568%2A%20">4115685</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/294">294</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:solaris-cde-nisplus-lock(7473)</comment>
<comment voter="Dik">sun bug: 4115685</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1026" seq="1999-1026">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420343&amp;w=2">19961220 Solaris 2.5 x86 aspppd (semi-exploitable-hole)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/292">292</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:sun-aspppd-tmp-symlink(7173)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1027" seq="1999-1027">
<status>Entry</status>
<desc>Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925880&amp;w=2">19980507 admintool mode 0777 in Solaris 2.6 HW3/98</ref>
<ref source="SUNBUG">4178998</ref>
<ref source="XF" url="http://xforce.iss.net/static/7296.php">solaris-admintool-world-writable(7296)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/290">290</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1028" seq="1999-1028">
<status>Entry</status>
<desc>Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92807524225090&amp;w=2">19990528 DoS against PC Anywhere</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/288">288</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2256.php">pcanywhere-dos(2256)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1029" seq="1999-1029">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92663402004280&amp;w=2">19990513 - J.J.F. / Hackers Team warns for SSHD 2.x brute force password hacking</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/277">277</ref>
<ref source="XF" url="http://xforce.iss.net/static/2193.php">ssh2-bruteforce(2193)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1030" seq="1999-1030">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92713790426690&amp;w=2">19990519 Denial of Service in Counter.exe version 2.70</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92707671717292&amp;w=2">19990519 Denial of Service in Counter.exe version 2.70</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/267">267</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:http-cgi-counter-long(2196)</comment>
<comment voter="Frech">XF:http-cgi-counter-long(2196)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1031" seq="1999-1031">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92713790426690&amp;w=2">19990519 Denial of Service in Counter.exe version 2.70</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92707671717292&amp;w=2">19990519 Denial of Service in Counter.exe version 2.70</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/267">267</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:http-cgi-counter-long(2196)</comment>
<comment voter="Frech">XF:http-cgi-counter-long(2196)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1032" seq="1999-1032">
<status>Entry</status>
<desc>Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-11.html">CA-1991-11</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-36.shtml">B-36</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/26">26</ref>
<ref source="XF" url="http://xforce.iss.net/static/584.php">ultrix-telnet(584)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1033" seq="1999-1033">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92647407427342&amp;w=2">19990511 Outlook Express Win98 bug</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92663402004275&amp;w=2">19990512 Outlook Express Win98 bug, addition.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/252">252</ref>
</refs>
<votes>
<accept count="2">Cole, Wall</accept>
<modify count="1">Frech</modify>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">(Task 2241)</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:outlook-pop3-dot-dos(8926)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1034" seq="1999-1034">
<status>Entry</status>
<desc>Vulnerability in login in AT&amp;T System V Release 4 allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-08.html">CA-1991-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/b-28.shtml">B-28</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/23">23</ref>
<ref source="XF" url="http://xforce.iss.net/static/583.php">sysv-login(583)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1035" seq="1999-1035">
<status>Entry</status>
<desc>IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS &quot;GET&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-019.asp">MS98-019</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q192/2/96.asp">Q192296</ref>
<ref source="XF" url="http://xforce.iss.net/static/1823.php">iis-get-dos(1823)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1036" seq="1999-1036">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref>
</refs>
<votes>
<accept count="1">Foat</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:cops-temp-file-symlink(7325)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1037" seq="1999-1037">
<status>Entry</status>
<desc>rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125986&amp;w=2">19980627 Re: vulnerability in satan, cops &amp; tiger</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7167.php">satan-rexsatan-symlink(7167)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3147">3147</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1038" seq="1999-1038">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the WORKDIR variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref>
</refs>
<votes>
<accept count="1">Foat</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:tiger-workdir-symlink(7326)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1039" seq="1999-1039">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030">19980502-01-P3030</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<reject count="1">Frech</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1040" seq="1999-1040">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89217373930054&amp;w=2">19980408 SGI O2 ipx security issue</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980501-01-P2869">19980501-01-P</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-055.shtml">I-055</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<noop count="1">Christey</noop>
<reject count="1">Frech</reject>
</votes>
<comments>
<comment voter="Christey">This candidate and CVE-1999-1501 are duplicates.  However,
CVE-1999-1501 will be REJECTed in favor of this candidate.
Add the following references:
BID:70
URL:http://www.securityfocus.com/bid/70
BID:71
URL:http://www.securityfocus.com/bid/71
XF:irix-ipxchk-ipxlink-ifs-commands(7365)
URL:http://xforce.iss.net/static/7365.php</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1041" seq="1999-1041">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10420">19980827 SCO mscreen vul.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90686250717719&amp;w=2">19980926 Root exploit for SCO OpenServer.</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-98.05a">SB-98.05a</ref>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-98.10.sco.mscreen">VB-98.10</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:sco-openserver-mscreen-bo(1379)</comment>
<comment voter="Christey">Possible dupe with CVE-1999-1185.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1042" seq="1999-1042">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/crmtmp-pub.shtml">19980813 CRM Temporary File Vulnerability</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reject count="3">Armstrong, Balinsky, Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:cisco-crm-file-vuln(1575)</comment>
<comment voter="Armstrong">I think that this is the same as Can-1999-1126</comment>
<comment voter="Balinsky">This is the same as CVE-1999-1126. Merge them.</comment>
<comment voter="Christey">DUPE CVE-1999-1126, as noted by others.
This candidate will be rejected.  CVE-1999-1126 will be
promoted.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1043" seq="1999-1043">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-007.asp">MS98-007</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Wall</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:exchange-dos(1223)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1044" seq="1999-1044">
<status>Entry</status>
<desc>Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.</desc>
<refs>
<ref source="COMPAQ" url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml">SSRT0495U</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml">I-050</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7431.php">dgux-advfs-softlinks(7431)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1045" seq="1999-1045">
<status>Entry</status>
<desc>pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88492978527261&amp;w=2">19980115 pnserver exploit..</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88490880523890&amp;w=2">19980115 [rootshell] Security Bulletin #7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90338245305236&amp;w=2">19980817 Re: Real Audio Server Version 5 bug?</ref>
<ref source="MISC" url="http://service.real.com/help/faq/serv501.html">http://service.real.com/help/faq/serv501.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7297.php">realserver-pnserver-remote-dos(7297)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6979">6979</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1046" seq="1999-1046">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990302 Multiple IMail Vulnerabilites</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/504">504</ref>
<ref source="XF" url="http://xforce.iss.net/static/1897.php">imail-imonitor-overflow(1897)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1047" seq="1999-1047">
<status>Entry</status>
<desc>When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94026690521279&amp;w=2">19991018 Gauntlet 5.0 BSDI warning</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94036662326185&amp;w=2">19991019 Re: Gauntlet 5.0 BSDI warning</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3397.php">gauntlet-bsdi-bypass(3397)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1048" seq="1999-1048">
<status>Entry</status>
<desc>Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10542">19980905 BASH buffer overflow, LiNUX x86 exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719555&amp;w=2">19970821 Buffer overflow in /bin/bash</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/1998/19980909">19980909 problem with very long pathnames</ref>
<ref source="XF" url="http://xforce.iss.net/static/3414.php">linux-bash-bo(3414)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8345">8345</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1049" seq="1999-1049">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91972006211238&amp;w=2">19990222 Severe Security Hole in ARCserve NT agents (fwd)</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:arcserve-agent-passwords(1822)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1050" seq="1999-1050">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34600">19991112 FormHandler.cgi</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34939">19991116 Re: FormHandler.cgi</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/798">798</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/799">799</ref>
<ref source="XF" url="http://xforce.iss.net/static/3550.php">formhandler-cgi-absolute-path(3550)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">Abstraction and definition issue: CD:SF-LOC suggests combining
issues of the same type.  Some people refer to &quot;directory
traversal&quot; and just mean .. problems; but there are other
issues (specifying an absolute pathname, using C: drive
letters, doing encodings) that, to my way of thinking, are
&quot;different.&quot;  Perhaps this should be split.

My brain hurts too much right now.  There are a couple
problems with the references and descriptions of CVE-1999-1050
and CVE-1999-1051.  I'm interpreting the underlying nature
of the problem(s) a little differently than others are.
Some of it may be due to differing definitions or thoughts
about what &quot;directory traversal vulnerabilities&quot; are.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1051" seq="1999-1051">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34939">19991116 Re: FormHandler.cgi</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:formhandler-cgi-reply-message(7782)</comment>
<comment voter="Christey">I view one of these as a configuration issue: FormHandler.cgi
*could* be configured to limit hard-coded pathnames to a single
directory which, while being an information leak, would still be
&quot;reasonably secure.&quot;  But by default, it's just not configured that
way.

My brain hurts too much right now.  There are a couple
problems with the references and descriptions of CVE-1999-1050
and CVE-1999-1051.  I'm interpreting the underlying nature
of the problem(s) a little differently than others are.
Some of it may be due to differing definitions or thoughts
about what &quot;directory traversal vulnerabilities&quot; are.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1052" seq="1999-1052">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93582550911564&amp;w=2">19990824 Front Page form_results</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:frontpage-formresults-world-readable(8362)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1053" seq="1999-1053">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>guestbook.pl cleanses user-inserted SSI commands by removing text between &quot;&lt;!--&quot; and &quot;--&gt;&quot; separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides &quot;--&gt;&quot;.</desc>
<refs>
<ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/27296">19990913 Guestbook perl script (long)</ref>
<ref source="VULN-DEV" url="http://www.securityfocus.com/archive/82/27560">19990916 Re: Guestbook perl script (error fix)</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33674">19991105 Guestbook.pl, sloppy SSI handling in Apache? (VD#2)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/776">776</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:guestbook-cgi-command-execution(7783)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1054" seq="1999-1054">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90675672323825&amp;w=2">19980925 Globetrotter  FlexLM 'lmdown' bogosity</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1055" seq="1999-1055">
<status>Entry</status>
<desc>Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel &quot;CALL Vulnerability.&quot;</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-018.asp">MS98-018</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/179">179</ref>
<ref source="XF" url="http://xforce.iss.net/static/1737.php">excel-call(1737)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1056" seq="1999-1056">
<status>Candidate</status>
<phase date="20050204">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1395.  Reason: This candidate is a duplicate of CVE-1999-1395.  Notes: All CVE users should reference CVE-1999-1395 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:vms-monitor-gain-privileges(7136)</comment>
<comment voter="Christey">DUPE CVE-1999-1395
This CAN is being rejected in favor of CVE-1999-1395 because
CVE-1999-1395 has more references.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1057" seq="1999-1057">
<status>Entry</status>
<desc>VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-07.html">CA-1990-07</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-04.shtml">B-04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/12">12</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7137.php">vms-analyze-processdump-privileges(7137)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1058" seq="1999-1058">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94337185023159&amp;w=2">19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94329968617085&amp;w=2">19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/3543.php">vermillion-ftp-cwd-overflow(3543)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/818">818</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1059" seq="1999-1059">
<status>Entry</status>
<desc>Vulnerability in rexec daemon (rexecd) in AT&amp;T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-04.html">CA-1992-04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/36">36</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3159.php">att-rexecd(3159)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1060" seq="1999-1060">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91937090211855&amp;w=2">19990217 Tetrix 1.13.16 is Vulnerable</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/340">340</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:tetrinet-dns-hostname-bo(7500)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1061" seq="1999-1061">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248518480&amp;w=2">19971004 HP Laserjet 4M Plus DirectJet Problem</ref>
<ref source="XF" url="http://xforce.iss.net/static/1876.php">laserjet-unpassworded(1876)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">CONFIRM:http://www.hp.com/cposupport/printers/support_doc/bpl
02914.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1062" seq="1999-1062">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248518480&amp;w=2">19971004 HP Laserjet 4M Plus DirectJet Problem</ref>
<ref source="XF" url="http://xforce.iss.net/static/1876.php">laserjet-unpassworded(1876)</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">DELREF:XF:laserjet-unpassworded(1876)
ADDREF:XF:hp-printer-flood(1818)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1063" seq="1999-1063">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14019">19990601 whois_raw.cgi problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/304">304</ref>
<ref source="XF" url="http://xforce.iss.net/static/2251.php">http-cgi-cdomain(2251)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1064" seq="1999-1064">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93555317429630&amp;w=2">19990822</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93582070508957&amp;w=2">19990824 Re: WindowMaker bugs (was sub:none )</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/596">596</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:windowmaker-bo(3249)</comment>
<comment voter="Frech">XF:windowmaker-bo(3249)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1065" seq="1999-1065">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94175465525422&amp;w=2">19991104 Palm Hotsync vulnerable to DoS attack</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:palm-hotsync-bo(7785)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1066" seq="1999-1066">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a &quot;Smurf&quot; style attack on another host, by spoofing the connection request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94589559631535&amp;w=2">19991222 Quake &quot;smurf&quot; - Quake War Utils</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="4">Christey, Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Christey">This is apparently a problem with the connection protocol.
See BUGTRAQ:19980522 NetQuake Protocol problem resulting in smurf like effect.
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925989&amp;w=2</comment>
<comment voter="Frech">XF:quake-udp-connection-dos(7862)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1067" seq="1999-1067">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420919&amp;w=2">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in webdist.cgi</ref>
<ref source="XF">sgi-machineinfo</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">I'd be a lot more confident in this vote if there was a more
concrete reference strongly associating webdist.cgi and machineinfo.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1068" seq="1999-1068">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419366&amp;w=2">19970723 DoS against Oracle Webserver 2.1 with PL/SQL stored procedures</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:oracle-webserver-dos(1812)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1069" seq="1999-1069">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7943">19971108 Security bug in iCat Suite version 3.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2126">2126</ref>
<ref source="XF" url="http://xforce.iss.net/static/1620.php">icat-carbo-server-vuln(1620)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">iCat's site at http://www.icat.com/ is shut down, and no
further support seems to be available.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1070" seq="1999-1070">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10021">19980725 Annex DoS</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:annex-ping-crash(2090)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1071" seq="1999-1071">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2">19981130 Security bugs in Excite for Web Servers 1.1</ref>
<ref source="XF" url="http://xforce.iss.net/static/1417.php">excite-world-write(1417)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1072" seq="1999-1072">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2">19981130 Security bugs in Excite for Web Servers 1.1</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1073" seq="1999-1073">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2">19981130 Security bugs in Excite for Web Servers 1.1</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1074" seq="1999-1074">
<status>Entry</status>
<desc>Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9138">19980501 Warning! Webmin Security Advisory</ref>
<ref source="CONFIRM" url="http://www.webmin.com/webmin/changes.html">http://www.webmin.com/webmin/changes.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/98">98</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1075" seq="1999-1075">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89025820612530&amp;w=2">19980318 AIX 4.1.5 DoS attack (aka &quot;Port 1025 problem&quot;)</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:aix-ttdbserver(813)
CONFIRM:APAR IX70400</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1076" seq="1999-1076">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the &quot;Log Out&quot; option and selecting a &quot;Cancel&quot; option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94096348604173&amp;w=2">19991026 Mac OS 9 Idle Lock Bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/745">745</ref>
</refs>
<votes>
<accept count="2">Cole, Foat</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:macos-idle-screenlock-bypass(7794)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1077" seq="1999-1077">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94149318124548&amp;w=2">19991101 Re: Mac OS 9 Idle Lock Bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/756">756</ref>
</refs>
<votes>
<accept count="2">Cole, Foat</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:macos-debug-screenlock-access(3426)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1078" seq="1999-1078">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9907&amp;L=ntbugtraq&amp;D=0&amp;P=10370&amp;F=P">19990729 WS_FTP Pro 6.0 Weak Password Encryption Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/547">547</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:wsftp-weak-password-encryption(8349)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1079" seq="1999-1079">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92601792420088&amp;w=2">19990506 AIX Security Fixes Update</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93587956513233&amp;w=2">19990825 AIX security summary</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/servlet/support/manager?rs=0&amp;rt=0&amp;org=apars&amp;doc=08E0B1A1B85472A1852567C90031BB36">IX80470</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/439">439</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:aix-ptrace-setgid(7487)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1080" seq="1999-1080">
<status>Entry</status>
<desc>rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92633694100270&amp;w=2">19990510 SunOS 5.7 rmmount, no nosuid.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93971288323395&amp;w=2">19991011</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/250">250</ref>
<ref source="SUNBUG">4205437</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8350">solaris-rmmount-gain-root(8350)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1081" seq="1999-1081">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MISC" url="http://www.w3.org/Security/Faq/wwwsf8.html#Q87">http://www.w3.org/Security/Faq/wwwsf8.html#Q87</ref>
<ref source="MISC" url="http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35">http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35</ref>
<ref source="XF" url="http://xforce.iss.net/static/2054.php">http-nov-files(2054)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1082" seq="1999-1082">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a &quot;......&quot; (modified dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93941794201059&amp;w=2">19991008 Jana webserver exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/699">699</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:jana-server-directory-traversal(6513)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1083" seq="1999-1083">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95730430727064&amp;w=2">20000502 Security Bug in Jana HTTP Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/699">699</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:jana-server-directory-traversal(6513)</comment>
<comment voter="Christey">MODIFY description - the attack is of the form &quot;/./../&quot;
(single dot followed by double-dot)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1084" seq="1999-1084">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The &quot;AEDebug&quot; registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222453431604&amp;w=2">19980622 Yet another &quot;get yourself admin rights exploit&quot;:</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q103/8/61.asp">Q103861</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-008.asp">MS00-008</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-029.shtml">K-029</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1044">1044</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Wall</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:nt-registry-permissions(4111)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1085" seq="1999-1085">
<status>Entry</status>
<desc>SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the &quot;SSH insertion attack.&quot;</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125884&amp;w=2">19980612 CORE-SDI-04: SSH insertion attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525878&amp;w=2">19980703 UPDATE: SSH insertion attack</ref>
<ref source="CISCO">20010627 Multiple SSH Vulnerabilities</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/13877">VU#13877</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1126.php">ssh-insert(1126)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1086" seq="1999-1086">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93214475111651&amp;w=2">19990715 NMRC Advisory: Netware 5 Client Hijacking</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/528">528</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:netware-ipx-session-spoof(2350)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1087" seq="1999-1087">
<status>Entry</status>
<desc>Internet Explorer 4 treats a 32-bit number (&quot;dotless IP address&quot;) in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS98-016.asp">MS98-016</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q168/6/17.asp">Q168617</ref>
<ref source="CONFIRM" url="http://www.microsoft.com/Windows/Ie/security/dotless.asp">http://www.microsoft.com/Windows/Ie/security/dotless.asp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7828">7828</ref>
<ref source="XF" url="http://xforce.iss.net/static/2209.php">ie-dotless(2209)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1088" seq="1999-1088">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.</desc>
<refs>
<ref source="HP">HPSBUX9701-050</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21</ref>
<ref source="XF" url="http://xforce.iss.net/static/2012.php">hp-chsh(2012)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1089" seq="1999-1089">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420285&amp;w=2">19961209 the HP Bug of the Week!</ref>
<ref source="HP">HPSBUX9701-049</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-16.shtml">H-16</ref>
<ref source="AUSCERT">AA-96.18</ref>
<ref source="XF">hp-chfn(2008)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1090" seq="1999-1090">
<status>Entry</status>
<desc>The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an &quot;ftp=yes&quot; line, which allows remote attackers to read and modify arbitrary files.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-15.html">CA-1991-15</ref>
<ref source="XF" url="http://xforce.iss.net/static/1844.php">ftp-ncsa(1844)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1091" seq="1999-1091">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419835&amp;w=2">19960903 [BUG] Vulnerability in TIN</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419839&amp;w=2">19960903 Re: BoS:      [BUG] Vulnerability in TIN</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420726&amp;w=2">19970329 symlink bug in tin/rtin</ref>
<ref source="XF" url="http://xforce.iss.net/static/431.php">tin-tmpfile(431)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1092" seq="1999-1092">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286179032648&amp;w=2">19991117 default permissions for tin</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:tin-insecure-permissions(7796)
Confirmed in changelog for 1.4.1
http://ftp.kreonet.re.kr/pub/tools/news/tin/v1.4/CHANGES</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1093" seq="1999-1093">
<status>Entry</status>
<desc>Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS98-011.asp">MS98-011</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q191/2/00.asp">Q191200</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1276.php">java-script-patch(1276)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1094" seq="1999-1094">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the &quot;mk:&quot; protocol, aka the &quot;MK Overrun security issue.&quot;</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88480839506155&amp;w=2">19980114 L0pht Advisory MSIE4.0(1)</ref>
<ref source="XF" url="http://xforce.iss.net/static/917.php">iemk-bug(917)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1095" seq="1999-1095">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87619953510834&amp;w=2">19971006 KSR[T] Advisory #3: updatedb / crontabs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88890116304676&amp;w=2">19980303 updatedb stuff</ref>
<ref source="BUGTRAQ">19980303 updatedb: sort patch</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88886870129518&amp;w=2">19980302 overwrite any file with updatedb</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Christey, Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:sort-tmp-file-symlink(7182)</comment>
<comment voter="Christey">This issue clearly has a long history.
CALDERA:CSSA-2002-SCO.21
URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0018.html
CALDERA:CSSA-2002-SCO.2
URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q1/0002.html
(There are 2 Caldera advisories because one is for Open UNIX
and UnixWare, and the other is for OpenServer)

XF:openserver-sort-symlink(9218)
URL:http://www.iss.net/security_center/static/9218.php</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1096" seq="1999-1096">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925954&amp;w=2">19980516 kde exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925959&amp;w=2">19980517 simple kde exploit fix</ref>
<ref source="XF" url="http://xforce.iss.net/static/1644.php">kde-klock-home-bo(1644)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1097" seq="1999-1097">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92586457816446&amp;w=2">19990504 Microsoft Netmeeting Hole</ref>
<ref source="XF" url="http://xforce.iss.net/static/2187.php">netmeeting-clipboard(2187)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1098" seq="1999-1098">
<status>Entry</status>
<desc>Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1995-03.html">CA-1995-03</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/f-12.shtml">F-12</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/516.php">bsd-telnet(516)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4881">4881</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1099" seq="1999-1099">
<status>Entry</status>
<desc>Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420184&amp;w=2">19961122 L0pht Kerberos Advisory</ref>
<ref source="XF" url="http://xforce.iss.net/static/65.php">kerberos-user-grab(65)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1100" seq="1999-1100">
<status>Entry</status>
<desc>Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixkey-pub.shtml">19980616 PIX Private Link Key Processing and Cryptography Issues</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-056.shtml">I-056</ref>
<ref source="XF" url="http://xforce.iss.net/static/1579.php">cisco-pix-parse-error(1579)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1101" seq="1999-1101">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12618">19990219 Yet Another password storing problem (was: Re: Possible Netscape Crypto Security Flaw)</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:lydia-ini-passwords(7501)
ADDREF:http://www.kabsoftware.com/lydia_history.txt (Version
History for Lydia, V3.3 - 11/24/00)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1102" seq="1999-1102">
<status>Entry</status>
<desc>lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.</desc>
<refs>
<ref source="MISC" url="http://www.phreak.org/archives/security/8lgm/8lgm.lpr">http://www.phreak.org/archives/security/8lgm/8lgm.lpr</ref>
<ref source="BUGTRAQ" url="http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm">19940307 8lgm Advisory Releases</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-25.shtml">E-25a</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1103" seq="1999-1103">
<status>Entry</status>
<desc>dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.05.dec">VB-96.05</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-18.shtml">G-18</ref>
<ref source="MISC" url="http://www.tao.ca/fire/bos/0209.html">http://www.tao.ca/fire/bos/0209.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7138.php">osf-dxconsole-gain-privileges(7138)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1104" seq="1999-1104">
<status>Entry</status>
<desc>Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418931&amp;w=2">19951205 Cracked: WINDOWS.PWL</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=88540877601866&amp;w=2">19980121 How to recover private keys for various Microsoft products</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88536273725787&amp;w=2">19980120 How to recover private keys for various Microsoft products</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q140/5/57.asp">Q140557</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/71.php">win95-nbsmbpwl(71)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1105" seq="1999-1105">
<status>Entry</status>
<desc>Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.</desc>
<refs>
<ref source="CONFIRM" url="http://www.zdnet.com/eweek/reviews/1016/tr42bug.html">http://www.zdnet.com/eweek/reviews/1016/tr42bug.html</ref>
<ref source="MISC" url="http://www.net-security.sk/bugs/NT/netware1.html">http://www.net-security.sk/bugs/NT/netware1.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7231.php">win95-netware-hidden-share(7231)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1106" seq="1999-1106">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9121">19980429 Security hole in kppp</ref>
<ref source="XF" url="http://xforce.iss.net/static/1643.php">kde-kppp-account-bo(1643)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/92">92</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1107" seq="1999-1107">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF" url="http://xforce.iss.net/static/1650.php">kde-kppp-path-bo(1650)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1108" seq="1999-1108">
<status>Candidate</status>
<phase date="20050204">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1107.  Reason: This candidate is a duplicate of CVE-1999-1107.  Notes: All CVE users should reference CVE-1999-1107 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="2">Foat, Wall</noop>
<reject count="2">Christey, Frech</reject>
</votes>
<comments>
<comment voter="Frech">Has exactly the same attributes as CVE-1999-1107.</comment>
<comment voter="Christey">DUPE CVE-1999-1107.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1109" seq="1999-1109">
<status>Entry</status>
<desc>Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94632241202626&amp;w=2">19991222 Re: procmail / Sendmail - five bugs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780566911948&amp;w=2">20000113 Re: procmail / Sendmail - five bugs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/904">904</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7760.php">sendmail-etrn-dos(7760)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1110" seq="1999-1110">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34675">19991114 IE 5.0 and Windows Media Player ActiveX object allow checking the existence of local files and directories</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/793">793</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:ie-mediaplayer-activex(7800)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1111" seq="1999-1111">
<status>Entry</status>
<desc>Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94218618329838&amp;w=2">19911109 ImmuniX OS Security Alert: StackGuard 1.21 Released</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/786">786</ref>
<ref source="XF" url="http://xforce.iss.net/static/3524.php">immunix-stackguard-bo(3524)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1112" seq="1999-1112">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the &quot;8BPS&quot; image type in a Photo Shop image header.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34066">19991109 Irfan view 3.07 buffer overflow</ref>
<ref source="MISC" url="http://stud4.tuwien.ac.at/~e9227474/main2.html">http://stud4.tuwien.ac.at/~e9227474/main2.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/3549.php">irfan-view32-bo(3549)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/781">781</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1113" seq="1999-1113">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89258194718577&amp;w=2">19980414 MacOS based buffer overflows...</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/75">75</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:eudora-ims-user-dos(7300) </comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1114" seq="1999-1114">
<status>Entry</status>
<desc>Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-15a.shtml">H-15A</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.17.suid_exec.vul">AA-96.17</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980405-01-I">19980405-01-I</ref>
<ref source="XF" url="http://xforce.iss.net/static/2100.php">ksh-suid_exec(2100)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/467">467</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1115" seq="1999-1115">
<status>Entry</status>
<desc>Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-04.html">CA-1990-04</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/a-30.shtml">A-30</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/7">7</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/6721.php">apollo-suidexec-unauthorized-access(6721)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1116" seq="1999-1116">
<status>Entry</status>
<desc>Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970503-01-PX">19970503-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/462">462</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1009">1009</ref>
<ref source="XF" url="http://xforce.iss.net/static/2108.php">sgi-runpriv(2108)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1117" seq="1999-1117">
<status>Entry</status>
<desc>lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;w=2&amp;r=1&amp;s=lquerypv&amp;q=b">19961124</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420195&amp;w=2">19961125 lquerypv fix</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420196&amp;w=2">19961125 AIX lquerypv</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/455">455</ref>
<ref source="XF" url="http://xforce.iss.net/static/1752.php">ibm-lquerypv(1752)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1118" seq="1999-1118">
<status>Entry</status>
<desc>ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/165&amp;type=0&amp;nav=sec.sba">00165</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/433">433</ref>
<ref source="XF" url="http://xforce.iss.net/static/817.php">sun-ndd(817)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1119" seq="1999-1119">
<status>Entry</status>
<desc>FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-09.html">CA-1992-09</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/41">41</ref>
<ref source="XF" url="http://xforce.iss.net/static/3154.php">aix-anon-ftp(3154)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1120" seq="1999-1120">
<status>Entry</status>
<desc>netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420403&amp;w=2">19970104 Irix: netprint story</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX">19961203-01-PX</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">19961203-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/395">395</ref>
<ref source="OSVDB" url="http://www.osvdb.org/993">993</ref>
<ref source="XF" url="http://xforce.iss.net/static/2107.php">sgi-netprint(2107)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1121" seq="1999-1121">
<status>Entry</status>
<desc>The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-06.html">CA-1992-06</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/38">38</ref>
<ref source="XF" url="http://xforce.iss.net/static/554.php">ibm-uucp(554)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/891">891</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1122" seq="1999-1122">
<status>Entry</status>
<desc>Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1989-02.html">CA-1989-02</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/ciac-08.shtml">CIAC-08</ref>
<ref source="SUNBUG">1019265</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/3">3</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6695">sun-restore-gain-privileges(6695)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1123" seq="1999-1123">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-07.html">CA-1991-07</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/107&amp;type=0&amp;nav=sec.sba">00107</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/21">21</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/22">22</ref>
<ref source="XF" url="http://xforce.iss.net/static/582.php">sun-sourcetapes(582)</ref>
</refs>
<votes>
<accept count="5">Cole, Dik, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Dik">sun bug: 1059621</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1124" seq="1999-1124">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.</desc>
<refs>
<ref source="MISC" url="http://packetstorm.securify.com/mag/phrack/phrack54/P54-08">http://packetstorm.securify.com/mag/phrack/phrack54/P54-08</ref>
</refs>
<votes>
<accept count="2">Cole, Wall</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1125" seq="1999-1125">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019796&amp;w=2">19970919 Instresting practises of Oracle [Oracle Webserver]</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:oracle-webserver-gain-root(7174)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1126" seq="1999-1126">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with &quot;DPR_&quot;.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/crmtmp-pub.shtml">19980813 CRM Temporary File Vulnerability</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-086.shtml">I-086</ref>
<ref source="XF" url="http://xforce.iss.net/static/1575.php">cisco-crm-file-vuln(1575)</ref>
</refs>
<votes>
<accept count="5">Armstrong, Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
<reject count="1">Balinsky</reject>
</votes>
<comments>
<comment voter="Balinsky">Duplicate of CVE-1999-1042</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1127" seq="1999-1127">
<status>Entry</status>
<desc>Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the &quot;Named Pipes Over RPC&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-017.asp">MS98-017</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q195/7/33.asp">Q195733</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/523.php">nt-spoolss(523)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1128" seq="1999-1128">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.</desc>
<refs>
<ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html">http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html</ref>
<ref source="MISC" url="http://members.tripod.com/~unibyte/iebug3.htm">http://members.tripod.com/~unibyte/iebug3.htm</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:http-ie-exec(462)</comment>
<comment voter="Christey">DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html
ADDREF MISC:http://focus.silversand.net/vulner/allbug/ie3.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1129" seq="1999-1129">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/26008">19990901 VLAN Security</ref>
<ref source="MISC" url="http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm">http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm</ref>
<ref source="XF" url="http://xforce.iss.net/static/3294.php">cisco-catalyst-vlan-frames(3294)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/615">615</ref>
</refs>
<votes>
<accept count="2">Foat, Frech</accept>
<noop count="2">Cole, Wall</noop>
</votes>
<comments>
<comment voter="CHANGE">[Foat changed vote from NOOP to ACCEPT]</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1130" seq="1999-1130">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93346448121208&amp;w=2">19990730 Netscape Enterprise Server yeilds source of JHTML</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93337389603117&amp;w=2">19990730 Netscape Enterprise Server yeilds source of JHTML</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/559">559</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:netscape-enterprise-view-jhtml(8352)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1131" seq="1999-1131">
<status>Entry</status>
<desc>Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.12.opengroup">VB-97.12</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-060.shtml">I-060</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980601-01-PX">19980601-01-PX</ref>
<ref source="XF" url="http://xforce.iss.net/static/1123.php">sgi-osf-dce-dos(1123)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1132" seq="1999-1132">
<status>Entry</status>
<desc>Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90763508011966&amp;w=2">19981005 NMRC Advisory - Lame NT Token Ring DoS</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90760603030452&amp;w=2">19981002 NMRC Advisory - Lame NT Token Ring DoS</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q179/1/57.asp">Q179157</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1399.php">token-ring-dos(1399)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1133" seq="1999-1133">
<status>Candidate</status>
<phase date="20020217">Modified</phase>
<desc>HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.</desc>
<refs>
<ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019776&amp;w=2">HPSBUX9709-069</ref>
<ref source="XF" url="http://xforce.iss.net/static/499.php">hp-vue-dt(499)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Christey">CHANGEREF:  chaneg XF reference to XF:hp-vue-dt(499)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1134" seq="1999-1134">
<status>Candidate</status>
<phase date="20020217">Modified</phase>
<desc>Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.</desc>
<refs>
<ref source="HP" url="http://packetstorm.securify.com/advisories/hpalert/008">HPSBUX9404-008</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-23.shtml">E-23</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2284.php">hp-vue(2284)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:hp-vue(2284)
Packetstorm URL is dead. Try another archive.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1135" seq="1999-1135">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.</desc>
<refs>
<ref source="HP" url="http://packetstorm.securify.com/advisories/hpalert/027">HPSBUX9504-027</ref>
<ref source="XF" url="http://xforce.iss.net/static/2284.php">hp-vue(2284)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1136" seq="1999-1136">
<status>Entry</status>
<desc>Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9807-081.html">HPSBUX9807-081</ref>
<ref source="HP" url="http://cert.ip-plus.net/bulletin-archive/msg00040.html">HPSBMP9807-005</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526177&amp;w=2">19980729 HP-UX Predictive &amp; Netscape SSL Vulnerabilities</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-081.shtml">I-081</ref>
<ref source="XF" url="http://xforce.iss.net/static/1413.php">mpeix-predictive(1413)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1137" seq="1999-1137">
<status>Entry</status>
<desc>The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/e-01.shtml">E-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
<ref source="XF" url="http://xforce.iss.net/static/549.php">sun-audio(549)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6436">6436</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1138" seq="1999-1138">
<status>Entry</status>
<desc>SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-13.html">CA-1993-13</ref>
<ref source="XF" url="http://xforce.iss.net/static/546.php">sco-homedir(546)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1139" seq="1999-1139">
<status>Entry</status>
<desc>Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-199801/0122.html">19980121 HP-UX CUE, CUD and LAND vulnerabilities</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019745&amp;w=2">19970901 HP UX Bug :)</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9801-074.html">HPSBUX9801-074</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-027b.shtml">I-027B</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2007.php">hp-cue(2007)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1140" seq="1999-1140">
<status>Entry</status>
<desc>Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88209041500913&amp;w=2">19971214 buffer overflows in cracklib?!</ref>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.16.CrackLib">VB-97.16</ref>
<ref source="XF" url="http://xforce.iss.net/static/1539.php">cracklib-bo(1539)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1141" seq="1999-1141">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420981&amp;w=2">19970515 MicroSolved finds hole in Ascom Timeplex Router Security</ref>
<ref source="XF" url="http://xforce.iss.net/static/1824.php">ascom-timeplex-debug(1824)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1142" seq="1999-1142">
<status>Entry</status>
<desc>SunOS 4.1.2 and earlier allows local users to gain privileges via &quot;LD_*&quot; environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-11.html">CA-1992-11</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/116">00116</ref>
<ref source="XF" url="http://xforce.iss.net/static/3152.php">sun-env(3152)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1143" seq="1999-1143">
<status>Entry</status>
<desc>Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-65.shtml">H-065</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970504-01-PX">19970504-01-PX</ref>
<ref source="XF" url="http://xforce.iss.net/static/2109.php">sgi-rld(2109)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1144" seq="1999-1144">
<status>Entry</status>
<desc>Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-051.html">HPSBUX9701-051</ref>
<ref source="XF" url="http://xforce.iss.net/static/2056.php">hp-mpower(2056)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1145" seq="1999-1145">
<status>Entry</status>
<desc>Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=1514">HPSBUX9701-044</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21</ref>
<ref source="XF" url="http://xforce.iss.net/static/2059.php">hp-glanceplus(2059)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1146" seq="1999-1146">
<status>Entry</status>
<desc>Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/advisories/1555">HPSBUX9405-011</ref>
<ref source="XF" url="http://xforce.iss.net/static/2060.php">hp-glanceplus-gpm(2060)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1147" seq="1999-1147">
<status>Entry</status>
<desc>Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91273739726314&amp;w=2">19981204 [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref>
<ref source="BUGTRAQ">19981207 Re: [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref>
<ref source="XF" url="http://xforce.iss.net/static/1430.php">pcm-dos-execute(1430)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3164">3164</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1148" seq="1999-1148">
<status>Entry</status>
<desc>FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-006.asp">MS98-006</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP">Q189262</ref>
<ref source="XF" url="http://xforce.iss.net/static/1215.php">iis-passive-ftp(1215)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1149" seq="1999-1149">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in CSM Proxy 4.1 allows remote attackers to cause a denial of service (crash) via a long string to the FTP port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525993&amp;w=2">19980716 S.A.F.E.R. Security Bulletin 980708.DOS.1.1</ref>
<ref source="XF" url="http://xforce.iss.net/static/1422.php">csm-proxy-dos(1422)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1150" seq="1999-1150">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Livingston Portmaster routers running ComOS use the same initial sequence number (ISN) for TCP connections, which allows remote attackers to conduct spoofing and hijack TCP sessions.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9723">19980630 Livingston Portmaster - ISN generation is loosy!</ref>
<ref source="XF" url="http://xforce.iss.net/static/1882.php">portmaster-fixed-isn(1882)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1151" seq="1999-1151">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90296493106214&amp;w=2">19980603 Compaq/Microcom 6000 DoS + more</ref>
<ref source="XF" url="http://xforce.iss.net/static/2089.php">microcom-dos(2089)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1152" seq="1999-1152">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90296493106214&amp;w=2">19980603 Compaq/Microcom 6000 DoS + more</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:microcom-brute-force(7301)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1153" seq="1999-1153">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11175">19981109 Several new CGI vulnerabilities</ref>
<ref source="XF" url="http://xforce.iss.net/static/1400.php">cgi-perl-mail-programs(1400)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1154" seq="1999-1154">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11175">19981109 Several new CGI vulnerabilities</ref>
<ref source="MISC" url="http://lakeweb.com/scripts/">http://lakeweb.com/scripts/</ref>
<ref source="XF" url="http://xforce.iss.net/static/1400.php">cgi-perl-mail-programs(1400)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="3">Christey, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Christey">I confirmed this problem via visual inspection of the
source code in http://www.lakeweb.com/scripts/filemail.zip
Line 82 has an insufficient check for shell metacharacters
that doesn't exclude semicolons.  Line 129 is the 
call where the metacharacters are injected.

Need to add &quot;filemail.pl&quot; to the description.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1155" seq="1999-1155">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11175">19981109 Several new CGI vulnerabilities</ref>
<ref source="MISC" url="http://lakeweb.com/scripts/">http://lakeweb.com/scripts/</ref>
<ref source="XF" url="http://xforce.iss.net/static/1400.php">cgi-perl-mail-programs(1400)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1156" seq="1999-1156">
<status>Entry</status>
<desc>BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.</desc>
<refs>
<ref source="NTBUGTRAQ">19990517 Vulnerabilities in BisonWare FTP Server 3.5</ref>
<ref source="XF" url="http://xforce.iss.net/static/2254.php">bisonware-port-crash(2254)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1157" seq="1999-1157">
<status>Entry</status>
<desc>Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP">Q192774</ref>
<ref source="XF" url="http://xforce.iss.net/static/3894.php">tcpipsys-icmp-dos(3894)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1158" seq="1999-1158">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.</desc>
<refs>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.09.Solaris.passwd.buffer.overrun.vul">AA-97.09</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/139&amp;type=0&amp;nav=sec.sba">00139</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<recast count="1">Christey</recast>
</votes>
<comments>
<comment voter="Frech">XF:solaris-pam-bo(7432)</comment>
<comment voter="Dik">sun bug: 4018347</comment>
<comment voter="Christey">These issues should be SPLIT per CD:SF-EXEC because the PAM
problem appears in different Solaris versions than
unix_scheme.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1159" seq="1999-1159">
<status>Entry</status>
<desc>SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91495920911490&amp;w=2">19981229 ssh2 security problem (and patch) (fwd)</ref>
<ref source="XF" url="http://xforce.iss.net/static/1471.php">ssh-privileged-port-forward(1471)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1160" seq="1999-1160">
<status>Entry</status>
<desc>Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.</desc>
<refs>
<ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420581&amp;w=2">HPSBUX9702-055</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-33.shtml">H-33</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7437.php">hp-ftpd-kftpd(7437)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1161" seq="1999-1161">
<status>Entry</status>
<desc>Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420102&amp;w=2">19961103 Re: Untitled</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420103&amp;w=2">19961104 ppl bugs</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html">HPSBUX9704-057</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-32.shtml">H-32</ref>
<ref source="AUSCERT">AA-97.07</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7438.php">hp-ppl(7438)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1162" seq="1999-1162">
<status>Entry</status>
<desc>Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-08.html">CA-1993-08</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/542.php">sco-passwd-deny(542)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1163" seq="1999-1163">
<status>Entry</status>
<desc>Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.</desc>
<refs>
<ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94347039929958&amp;w=2">HPSBUX9911-105</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7439.php">hp-ssp(7439)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1164" seq="1999-1164">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93041631215856&amp;w=2">19990625 Outlook denial of service</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:outlook-xuidl-dos(8356)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1165" seq="1999-1165">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93268249021561&amp;w=2">19990721 old gnu finger bugs</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/2478">19950317 GNU finger 1.37 executes ~/.fingerrc with gid root</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/535">535</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:gnu-finger-privilege-dropping(7175)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1166" seq="1999-1166">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/18156">19990711 Linux 2.0.37 segment limit bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/523">523</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">(Task 2253)</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:linux-segment-limit-privileges(11202)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1167" seq="1999-1167">
<status>Entry</status>
<desc>Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.</desc>
<refs>
<ref source="CONFIRM" url="http://www.wired.com/news/technology/0,1282,20677,00.html">http://www.wired.com/news/technology/0,1282,20677,00.html</ref>
<ref source="MISC" url="http://www.wired.com/news/technology/0,1282,20636,00.html">http://www.wired.com/news/technology/0,1282,20636,00.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7252.php">thirdvoice-cross-site-scripting(7252)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1168" seq="1999-1168">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12640">19990220 ISS install.iss security hole</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:iss-temp-files(1793)
ADDREF:http://www.securityfocus.com/archive/1/12679</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1169" seq="1999-1169">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12284">19990204 NOBO denial of service</ref>
</refs>
<votes>
<accept count="1">Foat</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:nobo-udp-packet-dos(7502)
ADDREF:http://www.securityfocus.com/archive/1/12378
ADDREF:http://web.cip.com.br/nobo/mudancas_en.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1170" seq="1999-1170">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the &quot;flags&quot; registry key to 1920.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91816507920544&amp;w=2">19990204 WS FTP Server Remote DoS Attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/218">218</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:imail-registry(1725)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1171" seq="1999-1171">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the &quot;flags&quot; registry key to 1920.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91816507920544&amp;w=2">19990204 WS FTP Server Remote DoS Attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/218">218</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:wsftp-registry(1726)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1172" seq="1999-1172">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11947">19990114 security hole in Maximizer</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">The discloser does not provide enough details to fully
understand what the problem is.  This makes it difficult
because if Maximizer has a concept of &quot;users&quot; and it is
designed to allow any user to modify any other user's data,
then this would not be a vulnerability or exposure, unless
that &quot;cross-user&quot; capability could be used to violate system
integrity, data confidentiality, or the like.  There are some
features of Maximizer 6.0 that, if abused, could allow someone
to do some bad things.  For example, an attacker could modify
the email addresses for contacts to redirect sales to
locations besides the customer.  There's also a capability of
assigning priorities and alarms, which could be susceptible to
an &quot;inconvenience attack&quot; at the very least, as well as
tie-ins to e-commerce capabilities.

The critical question becomes: &quot;how is this data shared&quot; in
the first place?  If it's through a network share or other
distribution method besides transferring the complete database
between sites, then this may be accessible to any attacker who
can mimic a Maximizer client (if there is such a thing as a
client), and this could be a vulnerability or exposure
according to the CVE definition.

However, since the Maximizer functionality is unknown to me
and not readily apparent from product documentation, it's hard
to know what to do about this one.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:maximizer-enterprise-calendar-modification(7590)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1173" seq="1999-1173">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91404045014047&amp;w=2">19981218 wordperfect 8 for linux security</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1174" seq="1999-1174">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the ZIP drive to power down, manually replacing the known disk with the target disk, and using the known password to access the target disk.</desc>
<refs>
<ref source="MISC" url="http://www.counterpane.com/crypto-gram-9812.html#doghouse">http://www.counterpane.com/crypto-gram-9812.html#doghouse</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1175" seq="1999-1175">
<status>Entry</status>
<desc>Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/wccpauth-pub.shtml">19980513 Cisco Web Cache Control Protocol Router Vulnerability</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-054.shtml">I-054</ref>
<ref source="XF" url="http://xforce.iss.net/static/1577.php">cisco-wccp-vuln(1577)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1176" seq="1999-1176">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in cidentd ident daemon allows local users to gain root privileges via a long line in the .authlie script.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88466930416716&amp;w=2">19980110 Cidentd</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90554230925545&amp;w=2">19980911 Re: security problems with jidentd</ref>
<ref source="MISC" url="http://spisa.act.uji.es/spi/progs/codigo/www.hack.co.za/exploits/daemon/ident/cidentd.c">http://spisa.act.uji.es/spi/progs/codigo/www.hack.co.za/exploits/daemon/ident/cidentd.c</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:cidentd-authlie-bo(7327)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1177" seq="1999-1177">
<status>Entry</status>
<desc>Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.</desc>
<refs>
<ref source="MISC" url="http://www.w3.org/Security/Faq/wwwsf4.html">http://www.w3.org/Security/Faq/wwwsf4.html</ref>
<ref source="CONFIRM" url="http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish">http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish</ref>
<ref source="XF" url="http://xforce.iss.net/static/2055.php">http-cgi-nphpublish(2055)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1178" seq="1999-1178">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via an HTTP request for the dumpenv.pl script.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/static/3223.php">sambar-dump-env(3223)</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9505 ">19980610 Sambar Server Beta BUG..</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1179" seq="1999-1179">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in man.sh CGI script, included in May 1998 issue of SysAdmin Magazine, allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9330">19980515 May SysAdmin man.sh security hole</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:mansh-execute-commands(7328)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1180" seq="1999-1180">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.</desc>
<refs>
<ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/NT/buffer.html">http://oliver.efri.hr/~crv/security/bugs/NT/buffer.html</ref>
<ref source="BUGTRAQ" url="http://www.tryc.on.ca/archives/bugtraq/1999_1/0612.html">19990216 Website Pro v2.0 (NT) Configuration Issues</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Cole, Foat</noop>
</votes>
<comments>
<comment voter="Christey">DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/buffer.html
ADDREF MISC:http://focus.silversand.net/vulner/allbug/buffer.html</comment>
<comment voter="Frech">XF:website-pro-args-commands(7529)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1181" seq="1999-1181">
<status>Entry</status>
<desc>Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980901-01-PX">19980901-01-PX</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-003.shtml">J-003</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7441.php">irix-register(7441)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1182" seq="1999-1182">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419318&amp;w=2">19970717 KSR[T] Advisory #2: ld.so</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419351&amp;w=2">19970722 ld.so vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88661732807795&amp;w=2">19980204 An old ld-linux.so hole</ref>
</refs>
<votes>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1183" seq="1999-1183">
<status>Candidate</status>
<phase date="20060705">Modified</phase>
<desc>System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980403-02-PX">19980403-02-PX</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980403-01-PX">19980403-01-PX</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8556">8556</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/809.php">sgi-mailcap(809)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:sgi-mailcap(809)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1184" seq="1999-1184">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420967&amp;w=2">19970513</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420970&amp;w=2">19970514 Re: ELM overflow</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:elm-term-bo(7183)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1185" seq="1999-1185">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.</desc>
<refs>
<ref source="BUGTRAQ">19980827 SCO mscreen vul.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90686250717719&amp;w=2">19980926 Root exploit for SCO OpenServer.</ref>
<ref source="CERT">VB-98.10</ref>
<ref source="SCO">98.05</ref>
<ref source="XF">sco-openserver-mscreen-bo(1379)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Possible dupe on CVE-1999-1041.</comment>
<comment voter="Christey">Possible dupe with CVE-1999-1041.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1186" seq="1999-1186">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418966&amp;w=2">19960102 rxvt security hole</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:rxvtpipe(425)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1187" seq="1999-1187">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419803&amp;w=2">19960826 [BUG] Vulnerability in PINE</ref>
<ref source="XF" url="http://xforce.iss.net/static/416.php">pine-tmpfile(416)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">CONFIRM:http://www.washington.edu/pine/changes.html</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1188" seq="1999-1188">
<status>Entry</status>
<desc>mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91479159617803&amp;w=2">19981227 mysql: mysqld creates world readable logs..</ref>
<ref source="XF" url="http://xforce.iss.net/static/1568.php">mysql-readable-log-files(1568)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1189" seq="1999-1189">
<status>Entry</status>
<desc>Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/36306">19991124 Netscape Communicator 4.7 - Navigator Overflows</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/36608">19991127 Netscape Communicator 4.7 - Navigator Overflows</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/822">822</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7884">netscape-long-argument-bo(7884)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1190" seq="1999-1190">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long &quot;From&quot; header in an e-mail message.</desc>
<refs>
<ref source="MISC" url="http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html">http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/801">801</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:emailclub-pop3-from-bo(7873)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1191" seq="1999-1191">
<status>Entry</status>
<desc>Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418335&amp;w=2">19970519 Re: Finally, most of an exploit for Solaris 2.5.1's ps.</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.18.solaris.chkey.buffer.overflow.vul">AA-97.18</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/144">00144</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/207">207</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7442.php">solaris-chkey-bo(7442)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1192" seq="1999-1192">
<status>Entry</status>
<desc>Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/143">00143</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/206">206</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7444.php">solaris-eeprom-bo(7444)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1193" seq="1999-1193">
<status>Entry</status>
<desc>The &quot;me&quot; user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-06.html">CA-1991-06</ref>
<ref source="XF" url="http://xforce.iss.net/static/581.php">next-me(581)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/20">20</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1194" seq="1999-1194">
<status>Entry</status>
<desc>chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-05.html">CA-1991-05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/17">17</ref>
<ref source="XF" url="http://xforce.iss.net/static/577.php">dec-chroot(577)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1195" seq="1999-1195">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92587579032534&amp;w=2">19990505 NAI AntiVirus Update Problem</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92588169005196&amp;w=2">19990505 NAI AntiVirus Update Problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/169">169</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:virusscan-ftp-update(8387)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1196" seq="1999-1196">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13451">19990427 NT/Exceed D.O.S.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/158">158</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:exceed-xserver-dos(7530)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1197" seq="1999-1197">
<status>Entry</status>
<desc>TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-12.html">CA-1990-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/14">14</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7140.php">sunos-tioccons-console-redirection(7140)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1198" seq="1999-1198">
<status>Entry</status>
<desc>BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml">B-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/11">11</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7141.php">nextstep-builddisk-root-access(7141)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1199" seq="1999-1199">
<status>Entry</status>
<desc>Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the &quot;sioux&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90252779826784&amp;w=2">19980807 YA Apache DoS attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90276683825862&amp;w=2">19980808 Debian Apache Security Update</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90286768232093&amp;w=2">19980810 Apache DoS Attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90280517007869&amp;w=2">19980811 Apache 'sioux' DOS fix for TurboLinux</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#apache">http://www.redhat.com/support/errata/rh51-errata-general.html#apache</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1200" seq="1999-1200">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vintra SMTP MailServer allows remote attackers to cause a denial of service via a malformed &quot;EXPN *@&quot; command.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222454131610&amp;w=2">19980720 DOS in Vintra systems Mailserver software.</ref>
<ref source="XF" url="http://xforce.iss.net/static/1617.php">vintra-mail-dos(1617)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1201" seq="1999-1201">
<status>Entry</status>
<desc>Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91849617221319&amp;w=2">19990206 New Windows 9x Bug:  TCP Chorusing</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/225">225</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7542">win-multiple-ip-dos(7542)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1202" seq="1999-1202">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>StarTech (1) POP3 proxy server and (2) telnet server allows remote attackers to cause a denial of service via a long USER command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525873&amp;w=2">19980703 Windows95 Proxy DoS Vulnerabilites</ref>
<ref source="XF" url="http://xforce.iss.net/static/2088.php">startech-pop3-overflow(2088)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1203" seq="1999-1203">
<status>Entry</status>
<desc>Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91868964203769&amp;w=2">19990210 Security problems in ISDN equipment authentication</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91888117502765&amp;w=2">19990212 PPP/ISDN multilink security issue - summary</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7498.php">ascend-ppp-isdn-dos(7498)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1204" seq="1999-1204">
<status>Entry</status>
<desc>Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default &quot;ANY&quot; address and result in access to more systems than intended by the administrator.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925912&amp;w=2">19980511 Firewall-1 Reserved Keywords Vulnerability</ref>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/config/keywords.html">http://www.checkpoint.com/techsupport/config/keywords.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/7293.php">fw1-user-defined-keywords-access(7293)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4416">4416</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1205" seq="1999-1205">
<status>Entry</status>
<desc>nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419195&amp;w=2">19960607 HP-UX B.10.01 vulnerability</ref>
<ref source="HP" url="http://packetstormsecurity.org/advisories/ibm-ers/96-08">HPSBUX9607-035</ref>
<ref source="CIAC">G-34</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/414">hp-nettune(414)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1206" seq="1999-1206">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93336970231857&amp;w=2">19990729 New ActiveX security problems in Windows 98 PCs</ref>
<ref source="CONFIRM" url="http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm">http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/555">555</ref>
</refs>
<votes>
<accept count="4">Armstrong, Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:systemwizard-modify-registry(7080)</comment>
<comment voter="Christey">CERT-VN:VU#22919
URL:http://www.kb.cert.org/vuls/id/22919
CERT-VN:VU#34453
URL:http://www.kb.cert.org/vuls/id/34453</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1207" seq="1999-1207">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.</desc>
<refs>
<ref source="MISC" url="http://www.efri.hr/~crv/security/bugs/NT/netxtray.html">http://www.efri.hr/~crv/security/bugs/NT/netxtray.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/907.php">netxray-bo(907)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1208" seq="1999-1208">
<status>Entry</status>
<desc>Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419337&amp;w=2">19970721 AIX ping, lchangelv, xlock fixes</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419330&amp;w=2">19970721 AIX ping (Exploit)</ref>
<ref source="XF" url="http://xforce.iss.net/static/803.php">ping-bo(803)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1209" seq="1999-1209">
<status>Entry</status>
<desc>Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88131151000069&amp;w=2">19971204 scoterm exploit</ref>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.14.scoterm">VB-97.14</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/690">sco-scoterm(690)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1210" seq="1999-1210">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87936891504885&amp;w=2">19971112 Digital Unix Security Problem</ref>
<ref source="XF" url="http://xforce.iss.net/static/613.php">dec-xterm(613)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1211" seq="1999-1211">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-02.html">CA-1991-02</ref>
<ref source="XF" url="http://xforce.iss.net/static/574.php">sun-intelnetd(574)</ref>
</refs>
<votes>
<accept count="5">Cole, Dik, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">CONFIRM:Sun Microsystems, Inc. Security Bulletin #00106 at
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/1
06&amp;type=0&amp;nav=sec.sba</comment>
<comment voter="Dik">sun bug:  1054669 1049886 1042370 1033809</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1212" seq="1999-1212">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-02.html">CA-1991-02</ref>
<ref source="XF" url="http://xforce.iss.net/static/574.php">sun-intelnetd(574)</ref>
</refs>
<votes>
<accept count="5">Cole, Dik, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Dik">sun bug:  1054669 1049886 1042370 1033809</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1213" seq="1999-1213">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.</desc>
<refs>
<ref source="HP" url="http://www2.dataguard.no/bugtraq/1997_4/0001.html">HPSBUX9710-070</ref>
<ref source="XF" url="http://xforce.iss.net/static/571.php">hp-telnetdos(571)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1214" seq="1999-1214">
<status>Entry</status>
<desc>The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.com/advisories/signals.txt">19970915 Vulnerability in I/O Signal Handling</ref>
<ref source="MISC" url="http://www.openbsd.com/advisories/signals.txt">http://www.openbsd.com/advisories/signals.txt</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11062">11062</ref>
<ref source="XF" url="http://xforce.iss.net/static/556.php">openbsd-iosig(556)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1215" seq="1999-1215">
<status>Entry</status>
<desc>LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-21.shtml">D-21</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-12.html">CA-1993-12</ref>
<ref source="XF" url="http://xforce.iss.net/static/545.php">novell-login(545)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1216" seq="1999-1216">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the &quot;no ip source-route&quot; command.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-07.html">CA-1993-07</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-15.shtml">D-15</ref>
<ref source="XF" url="http://xforce.iss.net/static/541.php">cisco-sourceroute(541)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1217" seq="1999-1217">
<status>Entry</status>
<desc>The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319435&amp;w=2">19970725 Re: NT security - why bother?</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319426&amp;w=2">19970723 NT security - why bother?</ref>
<ref source="XF" url="http://xforce.iss.net/static/526.php">nt-path(526)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1218" seq="1999-1218">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-04.html">CA-1993-04</ref>
<ref source="XF" url="http://xforce.iss.net/static/522.php">amiga-finger(522)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1219" seq="1999-1219">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1994-13.html">CA-1994-13</ref>
<ref source="AUSCERT">AA-94.04a</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-33.shtml">E-33</ref>
<ref source="XF" url="http://xforce.iss.net/static/511.php">sgi-prn-mgr(511)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/468">468</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1220" seq="1999-1220">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7527">19970824 Vulnerability in Majordomo</ref>
<ref source="XF" url="http://xforce.iss.net/static/502.php">majordomo-advertise(502)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1221" seq="1999-1221">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420141&amp;w=2">19961117 Digital Unix v3.x (v4.x?) security vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/399.php">dgux-chpwd(399)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1222" seq="1999-1222">
<status>Entry</status>
<desc>Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q188/5/71.ASP">Q188571</ref>
<ref source="XF" url="http://xforce.iss.net/static/3893.php">dns-netbtsys-dos(3893)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1223" seq="1999-1223">
<status>Entry</status>
<desc>IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q187/5/03.asp">Q187503</ref>
<ref source="XF" url="http://xforce.iss.net/static/3892.php">url-asp-av(3892)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1224" seq="1999-1224">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87635124302928&amp;w=2">19971008 L0pht Advisory: IMAP4rev1 imapd server</ref>
<ref source="XF" url="http://xforce.iss.net/static/349.php">imapd-core(349)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1225" seq="1999-1225">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7526">19970824 Serious security flaw in rpc.mountd on several operating systems.</ref>
<ref source="XF" url="http://xforce.iss.net/static/347.php">mountd-file-exists(347)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1226" seq="1999-1226">
<status>Entry</status>
<desc>Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.</desc>
<refs>
<ref source="MISC" url="http://www.securiteam.com/exploits/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html">http://www.securiteam.com/exploits/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/3436.php">netscape-huge-key-dos(3436)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1227" seq="1999-1227">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.</desc>
<refs>
<ref source="MISC" url="http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html">http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html</ref>
<ref source="MISC" url="http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html">http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/3334.php">ethereal-dev-capturec-root(3334)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1228" seq="1999-1228">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Various modems that do not implement a guard time, or are configured with a guard time of 0, can allow remote attackers to execute arbitrary modem commands such as ATH, ATH0, etc., via a &quot;+++&quot; sequence that appears in ICMP packets, the subject of an e-mail message, IRC commands, and others.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90695973308453&amp;w=2">19980927 1+2=3, +++ATH0=Old school DoS</ref>
<ref source="MISC" url="http://www.macintouch.com/modemsecurity.html">http://www.macintouch.com/modemsecurity.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/3320.php">global-village-modem-dos(3320)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1229" seq="1999-1229">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8590">19980225 Quake 2 Linux 3.13 (and lower) allow users to read arbitrary files</ref>
<ref source="XF" url="http://xforce.iss.net/static/733.php">linux-quake2(733)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1230" seq="1999-1230">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8282">19971224 Quake II Remote Denial of Service</ref>
<ref source="XF" url="http://xforce.iss.net/static/698.php">quake2-dos(698)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1231" seq="1999-1231">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14758">19990609 ssh advirsory</ref>
<ref source="XF" url="http://xforce.iss.net/static/2276.php">ssh-leak(2276)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1232" seq="1999-1232">
<status>Candidate</status>
<phase date="20060503">Modified</phase>
<desc>Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420994&amp;w=2">19970516 Irix and WWW</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8559">8559</ref>
<ref source="XF" url="http://xforce.iss.net/static/3316.php">sgi-day5datacopier(3316)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1233" seq="1999-1233">
<status>Entry</status>
<desc>IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the &quot;Domain Resolution&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp">MS99-039</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q241/5/62.asp">241562</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/657">657</ref>
<ref source="XF" url="http://xforce.iss.net/static/3306.php">iis-unresolved-domain-access(3306)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1234" seq="1999-1234">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94096671308565&amp;w=2">19991026 Re: LSA vulnerability on NT40 SP5</ref>
<ref source="XF" url="http://xforce.iss.net/static/3293.php">msrpc-samr-open-dos(3293)</ref>
</refs>
<votes>
<accept count="3">Cole, Frech, Wall</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1235" seq="1999-1235">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing (&quot;shoulder surfing&quot;) another user to read the information from the status bar when the user moves the mouse over a link.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://ntbugtraq.ntadvice.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9904&amp;L=NTBUGTRAQ&amp;P=R179">19990331 Minor Bug in IE5.0</ref>
<ref source="NTBUGTRAQ" url="http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html">19990825 IE5 FTP password exposure &amp; index.dat null ACL problem</ref>
<ref source="XF" url="http://xforce.iss.net/static/3289.php">nt-ie5-user-ftp-password(3289)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Wall</accept>
</votes>
<comments>
<comment voter="CHANGE">[Foat changed vote from NOOP to ACCEPT]</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1236" seq="1999-1236">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9910&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=662">19991001 Vulnerabilities in the Internet Anywhere Mail Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/731">731</ref>
<ref source="XF" url="http://xforce.iss.net/static/3285.php">iams-passwords-plaintext(3285)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1237" seq="1999-1237">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14384">19990606 Buffer overflows in smbval library</ref>
<ref source="XF" url="http://xforce.iss.net/static/2272.php">smbvalid-bo(2272)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1238" seq="1999-1238">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/advisories/1531">HPSBUX9409-017</ref>
<ref source="XF" url="http://xforce.iss.net/static/2262.php">hp-core-diag-fileset(2262)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1239" seq="1999-1239">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/advisories/1559">HPSBUX9407-015</ref>
<ref source="XF" url="http://xforce.iss.net/static/2261.php">hp-xauthority(2261)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1240" seq="1999-1240">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/5784">19961126 Major Security Vulnerabilities in Remote CD Databases</ref>
<ref source="XF" url="http://xforce.iss.net/static/2203.php">cddbd-bo(2203)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1241" seq="1999-1241">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.</desc>
<refs>
<ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html">http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/2173.php">ie-filesystemobject(2173)</ref>
</refs>
<votes>
<accept count="3">Cole, Frech, Wall</accept>
<noop count="2">Christey, Foat</noop>
</votes>
<comments>
<comment voter="Christey">DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html
ADDREF MISC:http://focus.silversand.net/vulner/allbug/activex4.html</comment>
<comment voter="Frech">Change MISC to http://www.securitybugware.org/NT/1018.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1242" seq="1999-1242">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://packetstormsecurity.org/advisories/hpalert/003">HPSBUX9402-003</ref>
<ref source="XF" url="http://xforce.iss.net/static/2162.php">hp-subnet-config(2162)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1243" seq="1999-1243">
<status>Entry</status>
<desc>SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-16.shtml">F-16</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373">19950301-01-P373</ref>
<ref source="XF" url="http://xforce.iss.net/static/2113.php">sgi-permissions(2113)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1244" seq="1999-1244">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IPFilter 3.2.3 through 3.2.10 allows local users to modify arbitrary files via a symlink attack on the saved output file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13303">19990415 FSA-99.04-IPFILTER-v3.2.10</ref>
<ref source="XF" url="http://xforce.iss.net/static/2087.php">ipfilter-temp-file(2087)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1245" seq="1999-1245">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>vacm ucd-snmp SNMP server, version 3.52, does not properly disable access to the public community string, which could allow remote attackers to obtain sensitive information.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/static/2086.php">ucd-snmpd-community(2086)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">http://www.securityfocus.com/archive/1/13130</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1246" seq="1999-1246">
<status>Entry</status>
<desc>Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q229/9/72.asp">Q229972</ref>
<ref source="XF" url="http://xforce.iss.net/static/2068.php">siteserver-directmail-passwords(2068)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1247" seq="1999-1247">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.</desc>
<refs>
<ref source="HP" url="http://packetstormsecurity.org/advisories/hpalert/006">HPSBUX9402-006</ref>
<ref source="XF" url="http://xforce.iss.net/static/2061.php">hp-dce9000(2061)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1248" seq="1999-1248">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://packetstormsecurity.org/advisories/hpalert/019">HPSBUX9411-019</ref>
<ref source="XF" url="http://xforce.iss.net/static/2058.php">hp-supportwatch(2058)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1249" seq="1999-1249">
<status>Entry</status>
<desc>movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-047.html">HPSBUX9701-047</ref>
<ref source="XF" url="http://xforce.iss.net/static/2057.php">hp-movemail(2057)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8099">8099</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1250" seq="1999-1250">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7506">19970819 Lasso CGI security hole (fwd)</ref>
<ref source="XF" url="http://xforce.iss.net/static/2044.php">http-cgi-lasso(2044)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1251" seq="1999-1251">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.</desc>
<refs>
<ref source="HP" url="http://packetstormsecurity.org/advisories/hpalert/043">HPSBUX9612-043</ref>
<ref source="XF" url="http://xforce.iss.net/static/2010.php">hp-audio-panic(2010)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1252" seq="1999-1252">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.15.sco">VB-96.15</ref>
<ref source="SCO" url="ftp://ftp.sco.COM/SSE/security_bulletins/SB.96:02a">96:002</ref>
<ref source="XF" url="http://xforce.iss.net/static/1966.php">sco-system-call(1966)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1253" seq="1999-1253">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.10.sco">VB-96.10</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB.96:01a">96:001</ref>
<ref source="XF" url="http://xforce.iss.net/static/1965.php">sco-kernel(1965)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1254" seq="1999-1254">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92099515709467&amp;w=2">19990308 Winfreeze EXPLOIT  Win9x/NT</ref>
<ref source="XF" url="http://xforce.iss.net/static/1947.php">win-redirects-freeze(1947)</ref>
</refs>
<votes>
<accept count="3">Cole, Frech, Wall</accept>
<modify count="1">Meunier</modify>
<noop count="2">Christey, Foat</noop>
</votes>
<comments>
<comment voter="Christey">Need to get feedback from MS on this.</comment>
<comment voter="Christey">(prompted from Pascal Meunier) should this be treated
as a general design issue with ICMP?  Or is it a specific
implementation flaw that only affects Reliant?</comment>
<comment voter="Meunier">The description is too narrow and incorrect.  Spoofed ICMP
redirect messages can be used to setup man-in-the-middle attacks
instead of a DoS.  There's no reason that this behavior would be
limited to Windows, as it is specified by the standard.  As I said
elsewhere, ICMP messages should not be acted upon without access
controls.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1255" seq="1999-1255">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.</desc>
<refs>
<ref source="MISC" url="http://www.rootshell.com/archive-j457nxiqi3gq59dv/199902/hyperseek.txt.html">http://www.rootshell.com/archive-j457nxiqi3gq59dv/199902/hyperseek.txt.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/1914.php">hyperseek-modify(1914)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1256" seq="1999-1256">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12744">19990304 Oracle Plaintext Password</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92056752115116&amp;w=2">19990304 Oracle Plaintext Password</ref>
<ref source="XF" url="http://xforce.iss.net/static/1902.php">oracle-passwords(1902)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1257" seq="1999-1257">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark).</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8134">19971126 Xyplex terminal server bug</ref>
<ref source="XF" url="http://xforce.iss.net/static/1825.php">xyplex-controlz-login(1825)</ref>
<ref source="XF" url="http://xforce.iss.net/static/1826.php">xyplex-question-login(1826)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1258" seq="1999-1258">
<status>Entry</status>
<desc>rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/102">00102</ref>
<ref source="XF" url="http://xforce.iss.net/static/1782.php">sun-pwdauthd(1782)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1259" seq="1999-1259">
<status>Entry</status>
<desc>Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q189/5/29.asp">Q189529</ref>
<ref source="XF" url="http://xforce.iss.net/static/1780.php">office-extraneous-data(1780)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1260" seq="1999-1260">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91910115718150&amp;w=2">19990215 KSR[T] Advisory #10: mSQL ServerStats</ref>
<ref source="XF" url="http://xforce.iss.net/static/1777.php">msql-serverstats(1777)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1261" seq="1999-1261">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12433">19990211 Rainbow Six Buffer Overflow.....</ref>
<ref source="XF" url="http://xforce.iss.net/static/1772.php">rainbowsix-nick-bo(1772)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1262" seq="1999-1262">
<status>Entry</status>
<desc>Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12231">19990202 Unsecured server in applets under Netscape</ref>
<ref source="XF" url="http://xforce.iss.net/static/1727.php">java-socket-open(1727)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1263" seq="1999-1263">
<status>Entry</status>
<desc>Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87773365324657&amp;w=2">19971024 Vulnerability in metamail</ref>
<ref source="XF" url="http://xforce.iss.net/static/1677.php">metamail-file-creation(1677)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1264" seq="1999-1264">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been expliticly disabled.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12048">19990121 WebRamp M3 remote network access bug</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91815321510224&amp;w=2">19990203 WebRamp M3 Perceived Bug</ref>
<ref source="XF" url="http://xforce.iss.net/static/1670.php">webramp-remote-access(1670)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1265" seq="1999-1265">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a &quot;(&quot; (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO.</desc>
<refs>
<ref source="BUGTRAQ">19980922 Re: WARNING! SMTP Denial of Service in SLmail ver 3.1</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90649892424117&amp;w=2">19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90650438826447&amp;w=2">19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1</ref>
<ref source="XF" url="http://xforce.iss.net/static/1664.php">slmail-parens-overload(1664)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Frech</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1266" seq="1999-1266">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/6978">19970613 rshd gives away usernames</ref>
<ref source="XF" url="http://xforce.iss.net/static/1660.php">rsh-username-leaks(1660)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1267" seq="1999-1267">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420906&amp;w=2">19970505 Hole in the KDE desktop</ref>
<ref source="XF" url="http://xforce.iss.net/static/1646.php">kde-flawed-ipc(1646)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1268" seq="1999-1268">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.</desc>
<refs>
<ref source="MISC" url="http://lists.kde.org/?l=kde-devel&amp;m=91560433413263&amp;w=2">http://lists.kde.org/?l=kde-devel&amp;m=91560433413263&amp;w=2</ref>
<ref source="XF" url="http://xforce.iss.net/static/1645.php">kde-konsole-hijack(1645)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1269" seq="1999-1269">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8506">19980206 serious security hole in KDE Beta 3</ref>
<ref source="XF" url="http://xforce.iss.net/static/1641.php">kde-kss-file-clobber(1641)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1270" seq="1999-1270">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.</desc>
<refs>
<ref source="MISC" url="http://lists.kde.org/?l=kde-devel&amp;m=90221974029738&amp;w=2">http://lists.kde.org/?l=kde-devel&amp;m=90221974029738&amp;w=2</ref>
<ref source="XF" url="http://xforce.iss.net/static/1639.php">kde-kmail-passphrase-leak(1639)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1271" seq="1999-1271">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9511">19980611 Unsecure passwords in Macromedia Dreamweaver</ref>
<ref source="XF" url="http://xforce.iss.net/static/1636.php">dreamweaver-weak-passwords(1636)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1272" seq="1999-1272">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
<ref source="XF" url="http://xforce.iss.net/static/1635.php">irix-cdrom-confidence(1635)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1273" seq="1999-1273">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8551">19980220 Simple way to bypass squid ACLs</ref>
<ref source="XF" url="http://xforce.iss.net/static/1627.php">squid-regexp-acl(1627)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1274" seq="1999-1274">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>iPass RoamServer 3.1 creates temporary files with world-writable permissions.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8307">19971229 iPass RoamServer 3.1</ref>
<ref source="XF" url="http://xforce.iss.net/static/1625.php">ipass-temporary-files(1625)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1275" seq="1999-1275">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9478">19970908 Password unsecurity in cc:Mail release 8</ref>
<ref source="XF" url="http://xforce.iss.net/static/1619.php">lotus-ccmail-passwords(1619)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1276" seq="1999-1276">
<status>Entry</status>
<desc>fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/1998/19981207">19981207 fte-console: does not drop its root priviliges</ref>
<ref source="XF" url="http://xforce.iss.net/static/1609.php">fte-console-privileges(1609)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1277" seq="1999-1277">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91487886514546&amp;w=2">19981224 BackWeb - Password issue (used by NAI for Corporate customer notification).</ref>
<ref source="XF" url="http://xforce.iss.net/static/1565.php">backweb-cleartext-passwords(1565)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1278" seq="1999-1278">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91470326629357&amp;w=2">19981225 Re: Nlog v1.0 Released - Nmap 2.x log management / analyzing tool</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91471400632145&amp;w=2">19981226 Nlog 1.1b released - security holes fixed</ref>
<ref source="XF" url="http://xforce.iss.net/static/1550.php">http-cgi-nlog-netbios(1550)</ref>
<ref source="XF">http-cgi-nlog-metachars(1549)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Frech</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1279" seq="1999-1279">
<status>Entry</status>
<desc>An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q138/0/01.asp">Q138001</ref>
<ref source="XF" url="http://xforce.iss.net/static/1548.php">snaserver-shared-folders(1548)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1280" seq="1999-1280">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11512">19981203 Remote Tools w/Exceed v.6.0.1.0 fer 95</ref>
<ref source="XF" url="http://xforce.iss.net/static/1547.php">exceed-cleartext-passwords(1547)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1281" seq="1999-1281">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11720">19981226 Breeze Network Server remote reboot and other bogosity.</ref>
<ref source="XF" url="http://xforce.iss.net/static/1544.php">breeze-remote-reboot(1544)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">There have been no followups to indicate that this issue has
been 
resolved in the production version, and as a benefit to the doubt,
this issue
transcends EX-BETA until proven otherwise.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1282" seq="1999-1282">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11543">19981210 RealSystem passwords</ref>
<ref source="XF" url="http://xforce.iss.net/static/1542.php">realsystem-readable-conf-file(1542)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1283" seq="1999-1283">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10320">19980814 URL exploit to crash Opera Browser</ref>
<ref source="XF" url="http://xforce.iss.net/static/1541.php">opera-slash-crash(1541)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">Will go along with a REJECT if MITRE decides on
EX-CLIENT-DOS.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1284" seq="1999-1284">
<status>Entry</status>
<desc>NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11131">19981105 various *lame* DoS attacks</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91063407332594&amp;w=2">19981107 Re: various *lame* DoS attacks</ref>
<ref source="MISC" url="http://www.dynamsol.com/puppet/text/new.txt">http://www.dynamsol.com/puppet/text/new.txt</ref>
<ref source="XF" url="http://xforce.iss.net/static/1540.php">nukenabber-timeout-dos(1540)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1285" seq="1999-1285">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91495921611500&amp;w=2">19981227 [patch] fix for urandom read(2) not interruptible</ref>
<ref source="XF" url="http://xforce.iss.net/static/1472.php">linux-random-read-dos(1472)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1286" seq="1999-1286">
<status>Candidate</status>
<phase date="20060623">Modified</phase>
<desc>addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420927&amp;w=2">19970509 Re: Irix: misc</ref>
<ref source="MISC" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/330">330</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8560">8560</ref>
<ref source="XF" url="http://xforce.iss.net/static/1433.php">irix-addnetpr(1433)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Christey, Cole, Foat</noop>
</votes>
<comments>
<comment voter="Christey">CHANGE DESC: &quot;via a symlink attack on the printers temporary file.&quot;
Add 5.3 as another affected version.

MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX
SGI:19961203-02-PX may solve this problem, but the advisory is so
vague that it is uncertain whether this was fixed or not. addnetpr is
not specifically named in the advisory, which names netprint, which is
not specified in the original Bugtraq post. In addition, the date on
the advisory is one day earlier than that of the Bugtraq post, though
that could be a difference in time zones. It seems plausible that the
problem had already been patched (the researcher did say &quot;There *was*
[a] race condition&quot;) so maybe SGI released this advisory after the
problem was publicized.

ADDREF BID:330
URL:http://www.securityfocus.com/bid/330

Note: this is a dupe of CVE-1999-1410, but CVE-1999-1410 will
be rejected in favor of CVE-1999-1286.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1287" seq="1999-1287">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.</desc>
<refs>
<ref source="CONFIRM" url="http://www.statslab.cam.ac.uk/~sret1/analog/security.html">http://www.statslab.cam.ac.uk/~sret1/analog/security.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/1410.php">analog-remote-file(1410)</ref>
</refs>
<votes>
<accept count="4">Armstrong, Cole, Frech, Stracener</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="CHANGE">[Foat changed vote from ACCEPT to NOOP]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1288" seq="1999-1288">
<status>Entry</status>
<desc>Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11397">19981119 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux</ref>
<ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/SA-1998.35.txt">SA-1998.35</ref>
<ref source="XF" url="http://xforce.iss.net/static/1406.php">samba-wsmbconf(1406)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1289" seq="1999-1289">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11233">19981111 WARNING: Another ICQ IP address vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/1398.php">icq-ip-info(1398)</ref>
</refs>
<votes>
<accept count="3">Cole, Frech, Wall</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">Override EX-BETA in this case, since ICQ is always in beta
and is 
widely run in production environments.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1290" seq="1999-1290">
<status>Entry</status>
<desc>Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91127951426494&amp;w=2">19981117 nftp vulnerability (fwd)</ref>
<ref source="CONFIRM" url="http://www.ayukov.com/nftp/history.html">http://www.ayukov.com/nftp/history.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/1397.php">nftp-bo(1397)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1291" seq="1999-1291">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10789">19981005 New Windows Vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/1383.php">nt-brkill(1383)</ref>
</refs>
<votes>
<accept count="3">Cole, Frech, Wall</accept>
<noop count="2">Christey, Foat</noop>
</votes>
<comments>
<comment voter="Christey">Need to get feedback from MS on this.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1292" seq="1999-1292">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise7.php">19980901 Remote Buffer Overflow in the Kolban Webcam32 Program</ref>
<ref source="XF" url="http://xforce.iss.net/static/1366.php">webcam32-buffer-overflow(1366)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1293" seq="1999-1293">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88413292830649&amp;w=2">19980106 Apache security advisory</ref>
<ref source="CONFIRM" url="http://www.apache.org/info/security_bulletin_1.2.5.html">http://www.apache.org/info/security_bulletin_1.2.5.html</ref>
</refs>
<votes>
<accept count="3">Armstrong, Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:apache-mod-proxy-dos(7249)
CONFIRM reference no longer seems to exist. BugTraq message
seems to be a confirmation/advisory, however.</comment>
<comment voter="CHANGE">[Foat changed vote from ACCEPT to NOOP]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1294" seq="1999-1294">
<status>Entry</status>
<desc>Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q146/6/04.asp">Q146604</ref>
<ref source="XF" url="http://xforce.iss.net/static/562.php">nt-filemgr(562)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1295" seq="1999-1295">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.16.transarc">VB-96.16</ref>
<ref source="XF" url="http://xforce.iss.net/static/7154.php">dfs-login-groups(7154)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:dfs-login-groups(7154)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1296" seq="1999-1296">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420878&amp;w=2">19970429 vulnerabilities in kerberos</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:kerberos-config-file-bo(7184)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1297" seq="1999-1297">
<status>Entry</status>
<desc>cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.</desc>
<refs>
<ref source="SUNBUG" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100452&amp;zone_32=10045%2A%20">1077164</ref>
<ref source="XF" url="http://xforce.iss.net/static/7482.php">sun-cmdtool-echo(7482)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1298" seq="1999-1298">
<status>Entry</status>
<desc>Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-97:03.sysinstall.asc">FreeBSD-SA-97:03</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7537.php">freebsd-sysinstall-ftp-password(7537)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6087">6087</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1299" seq="1999-1299">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>rcp on various Linux systems including Red Hat 4.0 allows a &quot;nobody&quot; user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420509&amp;w=2">19970203 Linux rcp bug</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:rcp-nobody-file-overwrite(7187)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1300" seq="1999-1300">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-31.shtml">B-31</ref>
</refs>
<votes>
<accept count="4">Armstrong, Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF: unicos-accton-read-files(7210)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1301" seq="1999-1301">
<status>Entry</status>
<desc>A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-31.shtml">G-31</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc">FreeBSD-SA-96:17</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7540.php">rzsz-command-execution(7540)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1302" seq="1999-1302">
<status>Candidate</status>
<phase date="20070105">Modified</phase>
<desc>Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.</desc>
<refs>
<ref source="CERT" url="http://ftp.cerias.purdue.edu/pub/advisories/cert/cert_bulletins/VB-94:01.sco">VB-94:01</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05</ref>
<ref source="SCO" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8797">8797</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7586">sco-pt_chmod(7586)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:sco-pt_chmod(7586)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1303" seq="1999-1303">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05</ref>
<ref source="SCO" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:sco-prwarn(7587)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1304" seq="1999-1304">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05</ref>
<ref source="SCO" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:sco-login(7588)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1305" seq="1999-1305">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in &quot;at&quot; program in SCO UNIX 4.2 and earlier allows local users to gain root access.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05</ref>
<ref source="SCO" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">94:001</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:sco-at(7589)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1306" seq="1999-1306">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the &quot;established&quot; keyword is set, which could allow attackers to bypass filters.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-20.html">CA-1992-20</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:cisco-acl-established(1248)
Possibly duplicate with CVE-1999-0162?</comment>
<comment voter="Christey">Might be a duplicate of CVE-1999-0162, but CVE-1999-0162 was
released in 1995, whereas this bug was released in 1992.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1307" seq="1999-1307">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_4/0676.html">19941209 Novell security advisory on sadc, urestore and the suid_exec feature</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-06.shtml">F-06</ref>
</refs>
<votes>
<accept count="4">Armstrong, Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF;novell-unixware-urestore-root(7211)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1308" seq="1999-1308">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://ciac.llnl.gov/ciac/bulletins/h-91.shtml">HPSBUX9611-041</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-09.shtml">H-09</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-91.shtml">H-91</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7594.php">hp-large-uid-gid(7594)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:hp-large-uid-gid(7594)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1309" seq="1999-1309">
<status>Entry</status>
<desc>Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0040.html">19940314 sendmail -d problem (OLD yet still here)</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0043.html">19940315 so...</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0042.html">19940315 anyone know details?</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0048.html">19940315 Security problem in sendmail versions 8.x.x</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0078.html">19940327 sendmail exploit script - resend</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities">CA-1994-12</ref>
<ref source="XF" url="http://xforce.iss.net/static/7155.php">sendmail-debug-gain-root(7155)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1310" seq="1999-1310">
<status>Candidate</status>
<phase date="20050204">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1022.  Reason: This candidate is a duplicate of CVE-1999-1022.  Notes: All CVE users should reference CVE-1999-1022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<reject count="2">Christey, Frech</reject>
</votes>
<comments>
<comment voter="Frech">DUPE CVE-1999-1022</comment>
<comment voter="Christey">As noted by Andre Frech, this is a duplicate of CVE-1999-1022.
The references from this candidate will be added to
CVE-1999-1022.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1311" seq="1999-1311">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.</desc>
<refs>
<ref source="HP" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">HPSBUX9701-046</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:hp-dt-bypass-auth(7668)
ACKNOWLEDGED-BY-VENDOR</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1312" seq="1999-1312">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-05.html">CA-1993-05</ref>
<ref source="XF" url="http://xforce.iss.net/static/7142.php">openvms-local-privilege-elevation(7142)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:openvms-local-privilege-elevation(7142)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1313" seq="1999-1313">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml">G-24</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:11.man.asc">FreeBSD-SA-96:11</ref>
<ref source="XF" url="http://xforce.iss.net/static/7348.php">bsd-man-command-sequence(7348)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:bsd-man-command-sequence(7348)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1314" seq="1999-1314">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml">G-24</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:10.mount_union.asc">FreeBSD-SA-96:10</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7429.php">unionfs-mount-ordering(7429)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:unionfs-mount-ordering(7429)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1315" seq="1999-1315">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-04.shtml">F-04</ref>
</refs>
<votes>
<accept count="4">Armstrong, Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:openvms-decnetosi-gain-privileges(7212)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1316" seq="1999-1316">
<status>Entry</status>
<desc>Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q247/9/75.asp">Q247975</ref>
<ref source="XF" url="http://xforce.iss.net/static/7391.php">passfilt-fullname(7391)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1317" seq="1999-1317">
<status>Entry</status>
<desc>Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92127046701349&amp;w=2">19990312 [ ALERT ] Case Sensitivity and Symbolic Links</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92162979530341&amp;w=2">19990314 AW: [ ALERT ] Case Sensitivity and Symbolic Links</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q222/1/59.asp">Q222159</ref>
<ref source="XF" url="http://xforce.iss.net/static/7398.php">nt-symlink-case(7398)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1318" seq="1999-1318">
<status>Entry</status>
<desc>/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.</desc>
<refs>
<ref source="SUNBUG" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&amp;zone_32=112193%2A%20">1121935</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7480.php">sun-su-path(7480)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1319" seq="1999-1319">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19960101-01-PX">19960101-01-PX</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7430.php">irix-object-server(7430)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:irix-object-server(7430)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1320" seq="1999-1320">
<status>Entry</status>
<desc>Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-01.shtml">D-01</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7213.php">netware-packet-spoofing-privileges(7213)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1321" seq="1999-1321">
<status>Entry</status>
<desc>Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.</desc>
<refs>
<ref source="BUGTRAQ" url="http://lists.netspace.org/cgi-bin/wa?A2=ind9811A&amp;L=bugtraq&amp;P=R4814">19981105 security patch for ssh-1.2.26 kerberos code</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4883">4883</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1322" seq="1999-1322">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91096758513985&amp;w=2">19981112 exchverify.log</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91133714919229&amp;w=2">19981117 Re: exchverify.log - update #1</ref>
<ref source="NTBUGTRAQ">19981125 Re: exchverify.log - update #2</ref>
<ref source="NTBUGTRAQ">19981216 Arcserve Exchange Client security issue being fixed</ref>
<ref source="NTBUGTRAQ">19990305 Cheyenne InocuLAN for Exchange plain text password still there</ref>
<ref source="NTBUGTRAQ">19990426 ArcServe Exchange Client Security Issue still unresolved</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1323" seq="1999-1323">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92370067416739&amp;w=2">19990409 NAV for MS Exchange &amp; Internet Email Gateways</ref>
</refs>
<votes>
<accept count="1">Prosser</accept>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:nav-admin-password(7543)</comment>
<comment voter="Prosser">This has been since corrected in later releases.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1324" seq="1999-1324">
<status>Entry</status>
<desc>VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-06.shtml">D-06</ref>
<ref source="XF" url="http://xforce.iss.net/static/7225.php">openvms-sysgen-enabled(7225)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1325" seq="1999-1325">
<status>Entry</status>
<desc>SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/c-19.shtml">C-19</ref>
<ref source="XF" url="http://xforce.iss.net/static/7261.php">vaxvms-sas-gain-privileges(7261)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1326" seq="1999-1326">
<status>Entry</status>
<desc>wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420401&amp;w=2">19970104 serious security bug in wu-ftpd v2.4</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420408&amp;w=2">19970105 BoS:  serious security bug in wu-ftpd v2.4 -- PATCH</ref>
<ref source="XF" url="http://xforce.iss.net/static/7169.php">wuftpd-abor-gain-privileges(7169)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1327" seq="1999-1327">
<status>Entry</status>
<desc>Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125826&amp;w=2">19980601 Re: SECURITY: Red Hat Linux 5.1 linuxconf bug (fwd)</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7239.php">linuxconf-lang-bo(7239)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6065">6065</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1328" seq="1999-1328">
<status>Entry</status>
<desc>linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19980826 [djb@redhat.com: Unidentified subject!]</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90383955231511&amp;w=2">19980823 Security concerns in linuxconf shipped w/RedHat 5.1</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7232.php">linuxconf-symlink-gain-privileges(7232)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6068">6068</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1329" seq="1999-1329">
<status>Entry</status>
<desc>Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit">http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7250.php">sysvinit-root-bo(7250)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1330" seq="1999-1330">
<status>Entry</status>
<desc>The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419259&amp;w=2">19970709 [linux-security] so-called snprintf() in db-1.85.4 (fwd)</ref>
<ref source="CONFIRM" url="http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html">http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#db">http://www.redhat.com/support/errata/rh42-errata-general.html#db</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7244.php">linux-libdb-snprintf-bo(7244)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1331" seq="1999-1331">
<status>Entry</status>
<desc>netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg">http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7245.php">netcfg-ethernet-dos(7245)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1332" seq="1999-1332">
<status>Entry</status>
<desc>gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88603844115233&amp;w=2">19980128 GZEXE - the big problem</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#gzip">http://www.redhat.com/support/errata/rh50-errata-general.html#gzip</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-308">DSA-308</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/7845">7845</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3812">3812</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7241.php">gzip-gzexe-tmp-symlink(7241)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1333" seq="1999-1333">
<status>Entry</status>
<desc>automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89042322924057&amp;w=2">19980319 ncftp 2.4.2 MkDirs bug</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp">http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7240.php">ncftp-autodownload-command-execution(7240)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6111">6111</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1334" seq="1999-1334">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88609666024181&amp;w=2">19980129 KSR[T] Advisory #7: filter</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#elm">http://www.redhat.com/support/errata/rh50-errata-general.html#elm</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Armstrong, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:elm-filter-getfilterrules-bo(7214)
XF:elm-filter2(711)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1335" seq="1999-1335">
<status>Entry</status>
<desc>snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp">http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp</ref>
<ref source="XF" url="http://xforce.iss.net/static/7251.php">cmusnmp-read-write(7251)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1336" seq="1999-1336">
<status>Entry</status>
<desc>3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93458364903256&amp;w=2">19990812 3com hiperarch flaw [hiperbomb.c]</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93492615408725&amp;w=2">19990816 Re: 3com hiperarch flaw [hiperbomb.c]</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6057">6057</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1337" seq="1999-1337">
<status>Entry</status>
<desc>FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93370073207984&amp;w=2">19990801 midnight commander vulnerability(?) (fwd)</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/9873.php">midnight-commander-data-disclosure(9873)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5921">5921</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1338" seq="1999-1338">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93259112204664&amp;w=2">19990721 Delegate creates directories writable for anyone</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:delegate-dgroot-permissions(8438)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1339" seq="1999-1339">
<status>Entry</status>
<desc>Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277766505061&amp;w=2">19990722 Re: ping -R causes kernel panic on a forwarding machine ( 2.2.5 a nd 2 .2.10)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277426802802&amp;w=2">19990722 Linux +ipchains+ ping -R</ref>
<ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz">http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7257.php">ipchains-ping-route-dos(7257)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6105">6105</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1340" seq="1999-1340">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94173799532589&amp;w=2">19991104 hylafax-4.0.2 local exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/765">765</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:hylafax-faxalter-gain-privs(3453)
Proper spelling of the product is HylaFAX (see
http://www.hylafax.org/)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1341" seq="1999-1341">
<status>Entry</status>
<desc>Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94061108411308&amp;w=2">19991022 Local user can send forged packets</ref>
<ref source="XF" url="http://xforce.iss.net/static/7858.php">linux-tiocsetd-forge-packets(7858)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1342" seq="1999-1342">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94042342010662&amp;w=2">19991017 ICQ ActiveList Server Exploit...</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:icq-activelist-udp-dos(7877)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1343" seq="1999-1343">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93986405412867&amp;w=2">19991013 Xerox DocuColor 4 LP D.O.S</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:xerox-docucolor4lp-dos(8041)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1344" seq="1999-1344">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Auto_FTP.pl script in Auto_FTP 0.2 stores usernames and passwords in plaintext in the auto_ftp.conf configuration file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923873006014&amp;w=2">19991005 Auto_FTP v0.02 Advisory</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:autoftp-plaintext-password(8045)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1345" seq="1999-1345">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923873006014&amp;w=2">19991005 Auto_FTP v0.02 Advisory</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:autoftp-shared-directory(8047)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1346" seq="1999-1346">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942774609925&amp;w=2">19991007 Problems with redhat 6 Xsession and pam.d/rlogin.</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:pam-rlogin-bypass(8315)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1347" seq="1999-1347">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942774609925&amp;w=2">19991007 Problems with redhat 6 Xsession and pam.d/rlogin.</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:xsession-bypass(8316)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1348" seq="1999-1348">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93220073515880&amp;w=2">19990630 linuxconf doesn't seem to deal correctly with /etc/pam.d/reboot</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:linuxconf-pam-shutdown-dos(8437)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1349" seq="1999-1349">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923679004325&amp;w=2">19991006 Omni-NFS/X Enterprise  (nfsd.exe) DOS</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:xlink-nfsd-dos(8317)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1350" seq="1999-1350">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93871933521519&amp;w=2">19990929 Multiple Vendor ARCAD permission problems</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:arcad-insecure-permissions(8318)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1351" seq="1999-1351">
<status>Entry</status>
<desc>Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the &quot;Listen to !nick &lt;soundname&gt; requests&quot; option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93845560631314&amp;w=2">19990924 Kvirc bug</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7761.php">kvirc-dot-directory-traversal(7761)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1352" seq="1999-1352">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93855134409747&amp;w=2">19990928 Re: [Fwd: Truth about ssh 1.2.27 vulnerabiltiy]</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:mknod-symlink(8319)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1353" seq="1999-1353">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to gain privielges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93698162708211&amp;w=2">19990907 MsgCore mailserver stores passwords in clear text</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:msgcore-plaintext-passwords(8271)
BUGTRAQ Reference is actually NTBUGTRAQ.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1354" seq="1999-1354">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93637687305327&amp;w=2">19990830 SoftArc's FirstClass E-mail Client</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93698283309513&amp;w=2">19990909 SoftArc's FirstClass E-mail Client</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">(Task 1766)</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:firstclass-plaintext-account(9874)</comment>
<comment voter="Christey">The following reference is for the FCCLIENT.LOG piece:
ADDREF NTBUGTRAQ:19990911 Re: SoftArc's FirstClass E-mail Client
URL:http://archives.neohapsis.com/archives/ntbugtraq/1999-q3/0189.html</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1355" seq="1999-1355">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93542118727732&amp;w=2">19990817 Compaq PFCUser account</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93654336516711&amp;w=2">19990905 Case ID  SSRT0620  - PFCUser account communication</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93759822430801&amp;w=2">19990915 (I) UPDATE - PFCUser Account,</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94183795025294&amp;w=2">19991105 UPDATE: SSRT0620 Compaq Foundation Agents v4.40B  PFCUser issues</ref>
<ref source="CONFIRM" url="http://www.compaq.com/products/servers/management/advisory.html">http://www.compaq.com/products/servers/management/advisory.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/3231.php">management-pfcuser(3231)</ref>
</refs>
<votes>
<accept count="5">Armstrong, Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1356" seq="1999-1356">
<status>Entry</status>
<desc>Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93646669500991&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93637792706047&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93759822830815&amp;w=2">19990917 Re: Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7763.php">compaq-smartstart-legal-notice(7763)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1357" seq="1999-1357">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a &quot;&lt;&quot; sign, and the 0x9b character to a &quot;&gt;&quot; sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915331626185&amp;w=2">19991005 Time to update those CGIs again</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:netscape-cgi-filtering-css(8274)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1358" seq="1999-1358">
<status>Entry</status>
<desc>When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q157/6/73.asp">Q157673</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7400.php">nt-user-policy-update(7400)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1359" seq="1999-1359">
<status>Entry</status>
<desc>When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/8/75.asp">Q163875</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7401.php">nt-group-policy-longname(7401)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1360" seq="1999-1360">
<status>Entry</status>
<desc>Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q160/6/50.asp">Q160650</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7402.php">nt-kernel-handle-dos(7402)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1361" seq="1999-1361">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925891&amp;w=2">19980509 coke.c</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:winnt-wins-packet-flood-dos(7329)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1362" seq="1999-1362">
<status>Entry</status>
<desc>Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q160/6/01.asp">Q160601</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7403.php">nt-win32k-dos(7403)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1363" seq="1999-1363">
<status>Entry</status>
<desc>Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/1/43.asp">Q163143</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7405.php">nt-nonpagedpool-dos(7405)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1364" seq="1999-1364">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q142/6/53.asp">Q142653</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7421.php">nt-threadcontext-dos(7421)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Wall</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:nt-threadcontext-dos(7421)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1365" seq="1999-1365">
<status>Entry</status>
<desc>Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93069418400856&amp;w=2">19990628 NT runs Explorer.exe, Taskmgr.exe etc. from wrong location</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93127894731200&amp;w=2">19990630 Update: NT runs explorer.exe, etc...</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2336">nt-login-default-folder(2336)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/0515">0515</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1366" seq="1999-1366">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92714118829880&amp;w=2">19990515 Pegasus Mail weak encryption</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:pegasus-weak-password-encryption(8430)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1367" seq="1999-1367">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users.</desc>
<refs>
<ref source="MISC" url="http://www.pcworld.com/news/article/0,aid,10842,00.asp">http://www.pcworld.com/news/article/0,aid,10842,00.asp</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(Task 2283)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1368" seq="1999-1368">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92652152723629&amp;w=2">19990512 InoculateIT 4.53 Real-Time Exchange Scanner Flawed</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=97439568517355&amp;w=2">20001116 InoculateIT AV Option for MS Exchange Server</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:inoculate-message-redirect-bypass(5602)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1369" seq="1999-1369">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92411181619110&amp;w=2">19990414 Real Media Server stores passwords in plain text</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:realserver-insecure-password(7544)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1370" seq="1999-1370">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92220197414799&amp;w=2">19990323 MSIE 5 installer disables screen saver</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:ie-ie5setup-disable-password(7545)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1371" seq="1999-1371">
<status>Candidate</status>
<phase date="20040723">Modified</phase>
<desc>Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100752221493&amp;w=2">19990308 Solaris &quot;/usr/bin/write&quot; bug</ref>
<ref source="MISC" url="http://www.securiteam.com/exploits/5ZP0O1P35O.html">http://www.securiteam.com/exploits/5ZP0O1P35O.html</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7546">solaris-write-bo(7546)</ref>
</refs>
<votes>
<accept count="2">Cole, Dik</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:solaris-write-bo(7546)</comment>
<comment voter="Christey">This appears to be a rediscovery of the problem for Solaris
2.8:
BUGTRAQ:20011114 /usr/bin/write (solaris2.x) Segmentation Fault
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100588255815773&amp;w=2</comment>
<comment voter="Dik">sun bug:  4218941</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1372" seq="1999-1372">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91966339502073&amp;w=2">19990219 Plaintext Password in Tractive's Remote Manager Software</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:triactive-remote-basic-auth(7548)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1373" seq="1999-1373">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91651770130771&amp;w=2">19990105 Re: Network Scan Vulnerability [SUMMARY]</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:powerhub-nmap-dos(7556)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1374" seq="1999-1374">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92523159819402&amp;w=2">19990427 Re: Shopping Carts exposing CC data</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:perlshop-cgi-obtain-information(7557)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1375" seq="1999-1375">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91877455626320&amp;w=2">19990211 Using FSO in ASP to view just about anything</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/230">230</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="3">Christey, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:iis-fso-read-files(7558)</comment>
<comment voter="Christey">Explicitly mention IIS</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1376" seq="1999-1376">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91632724913080&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91638375309890&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:frontpage-ext-fpcount-crash(5494)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1377" seq="1999-1377">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.</desc>
<refs>
<ref source="MISC" url="http://pulhas.org/phrack/55/P55-07.html">http://pulhas.org/phrack/55/P55-07.html</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:download-cgi-directory-traversal(8279)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1378" seq="1999-1378">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93250710625956&amp;w=2">19990917 improper chroot in dbmlparser.exe</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(Task 2284)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1379" seq="1999-1379">
<status>Entry</status>
<desc>DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93348057829957&amp;w=2">19990730 Possible Denial Of Service using DNS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93433758607623&amp;w=2">19990810 Possible Denial Of Service using DNS</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos">AL-1999.004</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-063.shtml">J-063</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7238.php">dns-udp-query-dos(7238)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1380" seq="1999-1380">
<status>Entry</status>
<desc>Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.</desc>
<refs>
<ref source="MISC" url="http://www.net-security.sk/bugs/NT/nu20.html">http://www.net-security.sk/bugs/NT/nu20.html</ref>
<ref source="MISC" url="http://mlarchive.ima.com/win95/1997/May/0342.html">http://mlarchive.ima.com/win95/1997/May/0342.html</ref>
<ref source="MISC" url="http://news.zdnet.co.uk/story/0,,s2065518,00.html">http://news.zdnet.co.uk/story/0,,s2065518,00.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7188.php">nu-tuneocx-activex-control(7188)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1381" seq="1999-1381">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90786656409618&amp;w=2">19981008 buffer overflow in dbadmin</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1382" seq="1999-1382">
<status>Entry</status>
<desc>NetWare NFS mode 1 and 2 implements the &quot;Read Only&quot; flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to &quot;Read Only,&quot; which NetWare-NFS changes to a setuid root program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88427711321769&amp;w=2">19980108 NetWare NFS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90295697702474&amp;w=2">19980812 Re: Netware NFS (fwd)</ref>
<ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551">http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7246.php">netware-nfs-file-ownership(7246)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1383" seq="1999-1383">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419868&amp;w=2">19960913 tee see shell problems</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1996_3/0503.html">19960919 Vulnerability in expansion of PS1 in bash &amp; tcsh</ref>
</refs>
<votes>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1384" seq="1999-1384">
<status>Entry</status>
<desc>Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420095&amp;w=2">19961030 (Another) vulnerability in new SGIs</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul">AA-96.08</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I">19961101-01-I</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/470">470</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7456.php">irix-systour(7456)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1385" seq="1999-1385">
<status>Entry</status>
<desc>Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420332&amp;w=2">19961219 Exploit for ppp bug (FreeBSD 2.1.0).</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc">FreeBSD-SA-96:20</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7465.php">ppp-bo(7465)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6085">6085</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1386" seq="1999-1386">
<status>Entry</status>
<desc>Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88932165406213&amp;w=2">19980308 another /tmp race: `perl -e' opens temp file not safely</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#perl">http://www.redhat.com/support/errata/rh50-errata-general.html#perl</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7243.php">perl-e-tmp-symlink(7243)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1387" seq="1999-1387">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420731&amp;w=2">19970402 Fatal bug in NT 4.0 server</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420732&amp;w=2">19970403 Fatal bug in NT 4.0 server (more comments)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420741&amp;w=2">19970407 DUMP of NT system crash</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1388" seq="1999-1388">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1994_2/0197.html">19940513 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994</ref>
<ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1994_2/0207.html">19940514 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_4/0755.html">19941218 Sun Patch Id #102060-01</ref>
</refs>
<votes>
<accept count="1">Dik</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Dik">sun bug: 1171499</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1389" seq="1999-1389">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the &quot;set host prompt&quot; setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the &quot;host: &quot; prompt.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925916&amp;w=2">19980511 3Com/USR Total Control Chassis dialup port access filters</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/99">99</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:3com-netserver-filter-bypass(7330)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1390" seq="1999-1390">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.</desc>
<refs>
<ref source="BUGTRAQ" url="http://darwin.bio.uci.edu/~mcoogan/bugtraq/msg00890.html">19980428 [Debian 2.0] /usr/bin/suidexec gives root access</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/94">94</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:suidmanager-suidexec-root-privileges(7304)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1391" seq="1999-1391">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml">B-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/10">10</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7143.php">nextstep-npd-root-access(7143)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:nextstep-npd-root-access(7143)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1392" seq="1999-1392">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml">B-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/9">9</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7144.php">nextstep-restore09-root-access(7144)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:nextstep-restore09-root-access(7144)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1393" seq="1999-1393">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Control Panel &quot;Password Security&quot; option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.</desc>
<refs>
<ref source="MISC" url="http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html">http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/532">532</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(Task 2285)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1394" seq="1999-1394">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93094058620450&amp;w=2">19990702 BSD-fileflags</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/510">510</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="2">Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(Task 2286)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1395" seq="1999-1395">
<status>Candidate</status>
<phase date="20091029">Modified</phase>
<desc>Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-18.html">CA-1992-18</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability">CA-92.16</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/51">51</ref>
<ref source="OSVDB" url="http://osvdb.org/59332">59332</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7136.php">vms-monitor-gain-privileges(7136)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:vms-monitor-gain-privileges(7136)
Duplicate of CVE-1999-1056? If not, indicate why in Analysis
comments.</comment>
<comment voter="Christey">Note that CVE-1999-1056</comment>
<comment voter="Christey">CVE-1999-1056 is in fact a duplicate.  This candidate will
be kept, and CVE-1999-1056 will be REJECTed, because this
candidate has more references.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1396" seq="1999-1396">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-15.html">CA-1992-15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/49">49</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7150.php">sun-integer-multiplication-access(7150)</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:sun-integer-multiplication-access(7150)</comment>
<comment voter="Dik">sun bug: 1069072 1071053</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1397" seq="1999-1397">
<status>Entry</status>
<desc>Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92242671024118&amp;w=2">19990323 Index Server 2.0 and the Registry</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92223293409756&amp;w=2">19990323 Index Server 2.0 and the Registry</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/476">476</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7559.php">iis-indexserver-reveal-path(7559)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1398" seq="1999-1398">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420921&amp;w=2">19970507 Irix: misc</ref>
<ref source="MISC" url="http://www.insecure.org/sploits/irix.xfsdump.html">http://www.insecure.org/sploits/irix.xfsdump.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/472">472</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:irix-xfsdump-symlink(7193)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1399" seq="1999-1399">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719552&amp;w=2">19970820 SpaceWare 7.3 v1.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/471">471</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:spaceware-hostname-command-execution(7194)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1400" seq="1999-1400">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The Economist screen saver 1999 with the &quot;Password Protected&quot; option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0007.html">19990603 Huge Exploit in NT 4.0 SP5 Screensaver with Password Protection Enabled</ref>
<ref source="NTBUGTRAQ" url="http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0009.html">19990603 Re: Huge Exploit in NT 4.0 SP5 Screensaver with Password Protecti on Enabled.</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92851653600852&amp;w=2">19990604 Official response from The Economist re: 1999 Screen Saver</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/466">466</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="2">Cole, Foat</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(Task 2287)
CONFIRM NTBUGTRAQ:19990604 Official response from The
Economist re: 1999 Screen Saver</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1401" seq="1999-1401">
<status>Candidate</status>
<phase date="20060309">Modified</phase>
<desc>Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961201-01-PX">19961201-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/463">463</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8563">8563</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7575.php">irix-searchbook-permissions(7575)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:irix-searchbook-permissions(7575)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1402" seq="1999-1402">
<status>Entry</status>
<desc>The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418317&amp;w=2">19970517 UNIX domain socket (Solarisx86 2.5)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248718482&amp;w=2">19971003 Solaris 2.6 and sockets</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/456">456</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7172.php">sun-domain-socket-permissions(7172)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1403" seq="1999-1403">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10771">19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/382">382</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1404" seq="1999-1404">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10771">19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/382">382</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1405" seq="1999-1405">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91936783009385&amp;w=2">19990217 snap utility for AIX.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91954824614013&amp;w=2">19990220 Re: snap utility for AIX.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/375">375</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:aix-snap-insecure-tmp(7560)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1406" seq="1999-1406">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526185&amp;w=2">19980729 Crash a redhat 5.1 linux box</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526192&amp;w=2">19980730 FD's 0..2 and suid/sgid procs (Was: Crash a redhat 5.1 linux box)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/372">372</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1407" seq="1999-1407">
<status>Entry</status>
<desc>ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88950856416985&amp;w=2">19980309 *sigh* another RH5 /tmp problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/368">368</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7294.php">initscripts-ifdhcpdone-dhcplog-symlink(7294)</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts">http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1408" seq="1999-1408">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420641&amp;w=2">19970305 Bug in connect() for aix 4.1.4 ?</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/352">352</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Christey, Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF: aix-hpux-connect-dos(7195)</comment>
<comment voter="Christey">BUGTRAQ:19970307 Re: Bug in connect() ?
URL:http://www.securityfocus.com/archive/1/Pine.HPP.3.92.970307195408.12139B-100000@wpax13.physik.uni-wuerzburg.de
BUGTRAQ:19970311 Re: Bug in connect() for aix 4.1.4 ?
URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&amp;mid=6419</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1409" seq="1999-1409">
<status>Entry</status>
<desc>The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.shmoo.com/mail/bugtraq/jul98/msg00064.html">19980703 more about 'at'</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90233906612929&amp;w=2">19980805 irix-6.2 &quot;at -f&quot; vulnerability</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/security/advisories/NetBSD-SA1998-004.txt.asc">NetBSD-SA1998-004</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/331">331</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7577.php">at-f-read-files(7577)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1410" seq="1999-1410">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420927&amp;w=2">19970509 Re: Irix: misc</ref>
<ref source="MISC" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/330">330</ref>
</refs>
<votes>
<noop count="2">Cole, Foat</noop>
<reject count="2">Christey, Frech</reject>
</votes>
<comments>
<comment voter="Christey">DUPE CVE-1999-1286
Need to add these references to CVE-1999-1286</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1411" seq="1999-1411">
<status>Entry</status>
<desc>The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.</desc>
<refs>
<ref source="DEBIAN" url="http://lists.debian.org/debian-security-announce/debian-security-announce-1998/msg00033.html">19981126 new version of fsp fixes security flaw</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91228908407679&amp;w=2">19981128 Debian: Security flaw in FSP</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91244712808780&amp;w=2">19981130 Debian: Security flaw in FSP</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91936850009861&amp;w=2">19990217 Debian GNU/Linux 2.0r5 released (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/316">316</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7574.php">fsp-anon-ftp-access(7574)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1412" seq="1999-1412">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14215">19990603 MacOS X system panic with CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/306">306</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(Task 2288)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1413" seq="1999-1413">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419549&amp;w=2">19960803 Exploiting Zolaris 2.4 ??  :)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/296">296</ref>
</refs>
<votes>
<modify count="2">Dik, Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:solaris-coredump-symlink(7196)</comment>
<comment voter="Dik">sun bug: 1208241

Also applies to set-uid executables that have made real
and effective uid identical</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1414" seq="1999-1414">
<status>Entry</status>
<desc>IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92765856706547&amp;w=2">19990525 Security Leak with IBM Netfinity Remote Control Software</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92902484317769&amp;w=2">19990609 IBM's response to &quot;Security Leak with IBM Netfinity Remote Control Software</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/284">284</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1415" seq="1999-1415">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-91.13.Ultrix.mail.vulnerability">CA-91.13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/27">27</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:bsd-binmail(515)
CA-1991-13 was superseded by CA-1995-02.</comment>
<comment voter="Christey">Is there overlap between CVE-1999-1415 and CVE-1999-1438?
Both CERT advisories are vague.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1416" seq="1999-1416">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10383">19980823 Solaris ab2 web server is junk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/253">253</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1417" seq="1999-1417">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10383">19980823 Solaris ab2 web server is junk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/253">253</ref>
</refs>
<votes>
<accept count="1">Dik</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Dik">sun bug: 4218283</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1418" seq="1999-1418">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ICQ99 ICQ web server build 1701 with &quot;Active Homepage&quot; enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists (&quot;404 Forbidden&quot;) versus when a file does not exist (&quot;404 not found&quot;).</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13508">19990501 Update: security hole in the ICQ-Webserver</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/246">246</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF;icq-webserver-gain-information(8229)
CONFIRM:http://online.securityfocus.com/archive/1/13655</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1419" seq="1999-1419">
<status>Entry</status>
<desc>Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/148">00148</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/219">219</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7535.php">sun-nisplus-bo(7535)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1420" seq="1999-1420">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526016&amp;w=2">19980720 N-Base Vulnerability Advisory</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526065&amp;w=2">19980722 N-Base Vulnerability Advisory Followup</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/212">212</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1421" seq="1999-1421">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526016&amp;w=2">19980720 N-Base Vulnerability Advisory</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526065&amp;w=2">19980722 N-Base Vulnerability Advisory Followup</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/212">212</ref>
</refs>
<votes>
<accept count="2">Cole, Foat</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1422" seq="1999-1422">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91540043023167&amp;w=2">19990102 PATH variable in zip-slackware 2.0.35</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/211">211</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:linux-path-execute-commands(7561)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1423" seq="1999-1423">
<status>Entry</status>
<desc>ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319160&amp;w=2">19970626 Solaris Ping bug (DoS)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319171&amp;w=2">19970627 SUMMARY: Solaris Ping bug (DoS)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319181&amp;w=2">19970627 Solaris Ping bug(inetsvc)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319180&amp;w=2">19971005 Solaris Ping Bug and other [bc] oddities</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/146">00146</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/209">209</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7492.php">ping-multicast-loopback-dos(7492)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1424" seq="1999-1424">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">00145</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/208">208</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:solaris-adminsuite-nisplus-password(7467)</comment>
<comment voter="Dik">sun bug:1237225</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1425" seq="1999-1425">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">00145</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/208">208</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:solaris-adminsuite-password-map-permissions(7468)</comment>
<comment voter="Dik">1236787</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1426" seq="1999-1426">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">00145</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/208">208</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:solaris-adminsuite-symlink(7469)</comment>
<comment voter="Dik">sun bug: 1262888</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1427" seq="1999-1427">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">00145</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/208">208</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:solaris-adminsuite-lock-file(7470)</comment>
<comment voter="Dik">sun bug: 1262888</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1428" seq="1999-1428">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">00145</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/208">208</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:solaris-adminsuite-database-manager(7471)</comment>
<comment voter="Dik">sun bug: 4005611</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1429" seq="1999-1429">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88419633507543&amp;w=2">19980105 Security flaw in either DIT TransferPro or Solaris</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/204">204</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:transferpro-devices-insecure-permissions(7305)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1430" seq="1999-1430">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91540043723185&amp;w=2">19990102 security problem with Royal daVinci</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/185">185</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:davinci-pim-access-information(7562)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1431" seq="1999-1431">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ZAK in Appstation mode allows users to bypass the &quot;Run only allowed apps&quot; policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91576100022688&amp;w=2">19990107 WinNT, ZAK and Office 97</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91606260910008&amp;w=2">19990109 WinNT, ZAK and Office 97</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/181">181</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:zak-bypass-restrictions(7563)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1432" seq="1999-1432">
<status>Entry</status>
<desc>Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525997&amp;w=2">19980716 Security risk with powermanagemnet on Solaris 2.6</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/160">160</ref>
<ref source="SUNBUG">4024179</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1433" seq="1999-1433">
<status>Entry</status>
<desc>HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525988&amp;w=2">19980715 JetAdmin software</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526067&amp;w=2">19980722 Re: JetAdmin software</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/157">157</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1434" seq="1999-1434">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525951&amp;w=2">19980713 Slackware Shadow Insecurity</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/155">155</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1435" seq="1999-1435">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525933&amp;w=2">19980710 socks5 1.0r5 buffer overflow..</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/154">154</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1436" seq="1999-1436">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the &quot;user&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525905&amp;w=2">19980708 WWW Authorization Gateway</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/152">152</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1437" seq="1999-1437">
<status>Entry</status>
<desc>ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525890&amp;w=2">19980707 ePerl: bad handling of ISINDEX queries</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525927&amp;w=2">19980710 ePerl Security Update Available</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/151">151</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1438" seq="1999-1438">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-91.01a.SunOS.mail.vulnerability">CA-1991-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/105 ">00105</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/15">15</ref>
</refs>
<votes>
<accept count="4">Cole, Dik, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:bsd-binmail(515)</comment>
<comment voter="Dik">sun bug: 1047340</comment>
<comment voter="Christey">Is there overlap between CVE-1999-1415 and CVE-1999-1438?
Both CERT advisories are vague.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1439" seq="1999-1439">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88419592307388&amp;w=2">19980102 Symlink bug with GCC 2.7.2</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88524071002939&amp;w=2">19980108 GCC Exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88492937727193&amp;w=2">19980115 GCC 2.7.? /tmp files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/146">146</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:gnu-gcc-tmp-symlink(7338)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1440" seq="1999-1440">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91522424302962&amp;w=2">19990101 Win32 ICQ 98a flaw</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/132">132</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:icq-long-filename(7564)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1441" seq="1999-1441">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103126047&amp;w=2">19980630 Serious Linux 2.0.34 security problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/111">111</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:linux-sigio-dos(7339)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1442" seq="1999-1442">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.</desc>
<refs>
<ref source="MISC" url="http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html">http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html</ref>
<ref source="MISC" url="http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html">http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/105">105</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:linux-k6-dos(7340)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1443" seq="1999-1443">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using &lt;CTRL&gt;&lt;ALT&gt;&lt;DEL&gt; and kill the process using the task manager, (2) booting the system from a separate disk, or (3) interrupting certain processes that execute while the system is booting.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125889&amp;w=2">19980602 Full Armor.... Fool Proof etc... bugs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125869&amp;w=2">19980609 Full Armor</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/103">103</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:full-armor-protection-bypass(7341)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1444" seq="1999-1444">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.</desc>
<refs>
<ref source="MISC" url="http://catless.ncl.ac.uk/Risks/20.41.html#subj4">http://catless.ncl.ac.uk/Risks/20.41.html#subj4</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(Task 2290)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1445" seq="1999-1445">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88637951600184&amp;w=2">19980202 imapd/ipop3d coredump in slackware 3.4</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:linux-imapd-ipop3d-dos(7345)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1446" seq="1999-1446">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the &quot;Clear History&quot; option, and are not visible when the user browses the folders because of tailored displays.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602837719654&amp;w=2">19970805 Re: Strange behavior regarding directory</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602837719655&amp;w=2">19970806 Re: Strange behavior regarding directory</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:http-ie-record(524)
In description, URL's should be URLs.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1447" seq="1999-1447">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526169&amp;w=2">19980728 Object tag crashes Internet Explorer 4.0</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526188&amp;w=2">19980730 Re: Object tag crashes Internet Explorer 4.0</ref>
</refs>
<votes>
<accept count="2">Cole, Wall</accept>
<noop count="2">Christey, Foat</noop>
</votes>
<comments>
<comment voter="Christey">BUGTRAQ:19980730 Re: Object tag crashes Internet Explorer 4.0
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526188&amp;w=2</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1448" seq="1999-1448">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526168&amp;w=2">19980729 Eudora exploit (was Microsoft Security Bulletin (MS98-008))</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1449" seq="1999-1449">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.</desc>
<refs>
<ref source="BUGTRAQ" url="http://oamk.fi/~jukkao/bugtraq/before-971202/0498.html">19970519 /dev/tcx0 crashes SunOS 4.1.4 on Sparc 20's</ref>
<ref source="MISC" url="http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html">http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:sun-tcx-dos(7197)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1450" seq="1999-1450">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.03b">SB-99.03b</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.06b">SB-99.06b</ref>
<ref source="SCO" url="ftp://ftp.sco.COM/SSE/sse020.ltr">SSE020</ref>
<ref source="SCO">SSE023</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:sco-rshd(7466)
Correct URLS are listed below:
Reference: SCO:SSE020
Reference:
URL:ftp://stage.caldera.com/pub/security/sse/sse020/sse020.ltr
Reference: SCO:SSE023
Reference:
URL:ftp://stage.caldera.com/pub/security/sse/sse023/sse023.ltr</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1451" seq="1999-1451">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q231/3/68.asp">Q231368</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref>
<ref source="XF" url="http://xforce.iss.net/static/3271.php">iis-samples-winmsdp(3271)</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Wall</accept>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1452" seq="1999-1452">
<status>Entry</status>
<desc>GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91764169410814&amp;w=2">19990129 ole objects in a &quot;secured&quot; environment?</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91822011021558&amp;w=2">19990205 Alert: MS releases GINA-fix for SP3, SP4, and TS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91788829326419&amp;w=2">19990129 ole objects in a &quot;secured&quot; environment?</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q214/8/02.asp">Q214802</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/198">198</ref>
<ref source="XF" url="http://xforce.iss.net/static/1975.php">nt-gina-clipboard(1975)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1453" seq="1999-1453">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91979439932341&amp;w=2">19990222 New IE4 vulnerability : the clipboard again.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/215">215</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:webbrowser-activex-view-clipboard(7565)
REMOVE:http://www.securityfocus.com/bid/215 This reference
deals with the Forms vulnerability only.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1454" seq="1999-1454">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Macromedia &quot;The Matrix&quot; screen saver on Windows 95 with the &quot;Password protected&quot; option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915027622690&amp;w=2">19991004 Weakness In &quot;The Matrix&quot; Screensaver For Windows</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="4">Christey, Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Christey">Looks like there might have been a re-discovery, though the
exploit is slightly different, and there is insufficient
detail to be certain that this isn't for a different
Matrix screen saver:
BUGTRAQ:20010801 matrix screensvr(16 Bit CineMac Screen Saver Engine) - [input validation error?]
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99669949717618&amp;w=2
BID:3130
URL:http://www.securityfocus.com/bid/3130</comment>
<comment voter="Frech">XF:matrix-win95-password-bypass(8280)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1455" seq="1999-1455">
<status>Entry</status>
<desc>RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q158/3/20.asp">Q158320</ref>
<ref source="XF" url="http://xforce.iss.net/static/7422.php">nt-rshsvc-ale-bypass(7422)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1456" seq="1999-1456">
<status>Entry</status>
<desc>thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10368">19980819 thttpd 2.04 released (fwd)</ref>
<ref source="CONFIRM" url="http://www.acme.com/software/thttpd/thttpd.html#releasenotes">http://www.acme.com/software/thttpd/thttpd.html#releasenotes</ref>
<ref source="XF" url="http://xforce.iss.net/static/1809.php">thttpd-file-read(1809)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1457" seq="1999-1457">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.</desc>
<refs>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_30.html">19991116 thttpd</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<reject count="1">Frech</reject>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1458" seq="1999-1458">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
<ref source="SCO" url="http://ftp1.support.compaq.com/public/dunix/v4.0d/ssrt0583u.README">SSRT0583U</ref>
<ref source="XF" url="http://xforce.iss.net/static/3138.php">du-at(3138)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Frech</accept>
<noop count="1">Stracener</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1459" seq="1999-1459">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>BMC PATROL Agent before 3.2.07 allows local users to gain root privileges via a symlink attack on a temporary file.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise10.php">19981102 BMC PATROL File Creation Vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/1388.php">bmc-patrol-file-create(1388)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/534">534</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="3">Christey, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Christey">The vendor has acknowledged this vulnerability via e-mail.  It
has been fixed.

NOTE: despite the fact that this candidate has been acknowledged
and fixed by the vendor, it is affected by the CVE content
decision CD:SF-LOC.  It cannot be accepted until the
CD:SF-LOC guidelines have been finalized.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1460" seq="1999-1460">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93198293132463&amp;w=2">19990713 Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93372579004129&amp;w=2">19990801 Re: Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/525">525</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="4">Christey, Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:patrol-snmp-file-creation(2347)</comment>
<comment voter="Christey">The vendor has acknowledged this vulnerability via e-mail.  It
has been fixed.

NOTE: despite the fact that this candidate has been acknowledged
and fixed by the vendor, it is affected by the CVE content
decision CD:SF-LOC.  It cannot be accepted until the
CD:SF-LOC guidelines have been finalized.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1461" seq="1999-1461">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420921&amp;w=2">19970507 Irix: misc</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I">20001101-01-I</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/381">381</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<reject count="1">Frech</reject>
</votes>
<comments>
<comment voter="Frech">Possible conflict with CVE-2000-0799.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1462" seq="1999-1462">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attacker to read portions of arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13440">19990426 FW: Security Notice: Big Brother 1.09b/c</ref>
<ref source="CONFIRM" url="http://bb4.com/README.CHANGES">http://bb4.com/README.CHANGES</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/142">142</ref>
<ref source="XF" url="http://xforce.iss.net/static/3755.php">http-cgi-bigbrother-bbhist(3755)</ref>
</refs>
<votes>
<accept count="5">Armstrong, Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1463" seq="1999-1463">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7219">19970710 A New Fragmentation Attack</ref>
<ref source="XF" url="http://xforce.iss.net/static/528.php">nt-frag(528)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
<comment voter="Frech">This issue is also listed under CVE-1999-0226.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1464" seq="1999-1464">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by Cisco bug CSCdk35564.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml">19981105 Cisco IOS DFS Access List Leakage</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-016.shtml">J-016</ref>
<ref source="XF" url="http://xforce.iss.net/static/1401.php">cisco-acl-leakage(1401)</ref>
</refs>
<votes>
<accept count="6">Armstrong, Balinsky, Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1465" seq="1999-1465">
<status>Candidate</status>
<phase date="20020228">Modified</phase>
<desc>Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as described by Cisco bug CSCdk43862.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml">19981105 Cisco IOS DFS Access List Leakage</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-016.shtml">J-016</ref>
<ref source="XF" url="http://xforce.iss.net/static/1401.php">cisco-acl-leakage(1401)</ref>
</refs>
<votes>
<accept count="6">Armstrong, Balinsky, Cole, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1466" seq="1999-1466">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the &quot;established&quot; keyword.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-20.html">CA-1992-20</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/53">53</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Christey, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:cisco-acl-established(1248)
Possible dupe with CVE-1999-0162.</comment>
<comment voter="Christey">This is not a dupe with CVE-1999-0162.  The Cisco advisory
referenced in CVE-1999-0162 says that affected Cisco versions
are 10.0 through 10.3.  This CAN deals with versions 8.2
through 9.1.  In addition, the date of release of
CVE-1999-0162 is June 1995; this CAN was released December
1992.  Both items include clear Cisco acknowledgement with
details, so we should conclude that  they are separate
problems, despite the vagueness of the reports.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1467" seq="1999-1467">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1989-07.html">CA-1989-07</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/5">5</ref>
<ref source="XF" url="http://xforce.iss.net/static/3165.php">sun-rcp(3165)</ref>
</refs>
<votes>
<accept count="5">Cole, Dik, Foat, Frech, Stracener</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Dik">sun bug: 1028958</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1468" seq="1999-1468">
<status>Entry</status>
<desc>rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.</desc>
<refs>
<ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-91.20.rdist.vulnerability">CA-91.20</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/31">31</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7160.php">rdist-popen-gain-privileges(7160)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8106">8106</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1469" seq="1999-1469">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93871926821410&amp;w=2">19990930 mini-sql Buffer Overflow</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:msql-w3auth-bo(8301)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1470" seq="1999-1470">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93034788412494&amp;w=2">19990624 Eastman Software Work Management 3.21</ref>
<ref source="XF" url="http://xforce.iss.net/static/2303.php">eastman-cleartext-passwords(2303)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/485">485</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1471" seq="1999-1471">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1989-01.html">CA-1989-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/4">4</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7152.php">bsd-passwd-bo(7152)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:bsd-passwd-bo(7152)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1472" seq="1999-1472">
<status>Entry</status>
<desc>Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87710897923098&amp;w=2">19971017 Security Hole in Explorer 4.0</ref>
<ref source="MISC" url="http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html">http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html</ref>
<ref source="CONFIRM" url="http://www.microsoft.com/Windows/ie/security/freiburg.asp">http://www.microsoft.com/Windows/ie/security/freiburg.asp</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/7/94.asp">Q176794</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="XF" url="http://xforce.iss.net/static/587.php">http-ie-spy(587)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7819">7819</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1473" seq="1999-1473">
<status>Entry</status>
<desc>When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the &quot;Page Redirect Issue.&quot;</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7426.php">ie-page-redirect(7426)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7818">7818</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1474" seq="1999-1474">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.</desc>
<refs>
<ref source="CONFIRM" url="http://www.microsoft.com/windows/ie/security/powerpoint.asp">http://www.microsoft.com/windows/ie/security/powerpoint.asp</ref>
<ref source="XF" url="http://xforce.iss.net/static/179.php">nt-ppt-patch(179)</ref>
</refs>
<votes>
<accept count="6">Armstrong, Cole, Foat, Frech, Stracener, Wall</accept>
</votes>
<comments>
<comment voter="Frech">Looks like CONFIRM URL is too old for Microsoft to keep
(currently cached at
http://www.google.com/search?q=cache:86loHcRhaL4:www.microsoft.com/ie/
security/powerpoint.htm+%22PowerPoint+Browsing+Security+Issue%22&amp;hl=en
). Same information is available at BugTraq at
http://www.securityfocus.com/cgi-bin/archive.pl?id=1&amp;mid=6724</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1475" seq="1999-1475">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/35483">19991119 ProFTPd - mod_sqlpw.c</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/812">812</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:proftpd-modsqlpw-insecure-passwords(8332)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1476" seq="1999-1476">
<status>Entry</status>
<desc>A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the &quot;Invalid Operand with Locked CMPXCHG8B Instruction&quot; problem.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/8/52.asp ">Q163852</ref>
<ref source="XF" url="http://xforce.iss.net/static/704.php">pentium-crash(704)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1477" seq="1999-1477">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28717">19990923 Linux GNOME exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/663">663</ref>
<ref source="XF" url="http://xforce.iss.net/static/3349.php">gnome-espeaker-local-bo(3349)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1478" seq="1999-1478">
<status>Entry</status>
<desc>The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827429589&amp;w=2">19990706 Bug in SUN's Hotspot VM</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93240220324183&amp;w=2">19990716 FW: (Review ID: 85125) Hotspot crashes bringing down webserver</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/522">522</ref>
<ref source="XF" url="http://xforce.iss.net/static/2348.php">sun-hotspot-vm(2348)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1479" seq="1999-1479">
<status>Candidate</status>
<phase date="20080304">Modified</phase>
<desc>The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9609">19980624 textcounter.pl SECURITY HOLE      </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2265">2265</ref>
<ref source="XF" url="http://xforce.iss.net/static/2052.php">http-cgi-textcounter(2052)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1480" seq="1999-1480">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/429">429</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:aix-acledit-aclput-symlink(7346)
CONFIRM:APAR IX79139</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1481" seq="1999-1481">
<status>Entry</status>
<desc>Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33295">19991025 [squid] exploit for external authentication problem</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33295">19991103 [squid]exploit for external authentication problem</ref>
<ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.2/bugs/">http://www.squid-cache.org/Versions/v2/2.2/bugs/</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/741">741</ref>
<ref source="XF" url="http://xforce.iss.net/static/3433.php">squid-proxy-auth-access(3433)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1482" seq="1999-1482">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-02-15&amp;msg=Pine.LNX.3.96.990219175605.9622A-100000@ferret.lmh.ox.ac.uk">19990219 Security hole: &quot;zgv&quot;</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:zgv-privilege-leak(1798)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1483" seq="1999-1483">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7041">19970619 svgalib/zgv</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF;linux-svgalib-dos(3412)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1484" seq="1999-1484">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719">19990924 Several ActiveX Buffer Overruns</ref>
<ref source="XF" url="http://xforce.iss.net/static/3310.php">msn-setup-bbs-activex-bo(3310)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/668">668</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1485" seq="1999-1485">
<status>Candidate</status>
<phase date="20060705">Modified</phase>
<desc>nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92818552106912&amp;w=2">19990531 IRIX 6.5 nsd virtual filesystem vulnerability</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8564">8564</ref>
<ref source="XF" url="http://xforce.iss.net/static/2246.php">sgi-nsd-view(2246)</ref>
<ref source="XF" url="http://xforce.iss.net/static/2247.php">sgi-nsd-create(2247)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/412">412</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1486" seq="1999-1486">
<status>Entry</status>
<desc>sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="CONFIRM" url="http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info">http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX75554&amp;apar=only">IX75554</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76853&amp;apar=only">IX76853</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76330&amp;apar=only">IX76330</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/408">408</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7675">aix-sadc-timex(7675)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1487" seq="1999-1487">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.</desc>
<refs>
<ref source="AIXAPAR" url="http://www-1.ibm.com/servlet/support/manager?rt=0&amp;rs=0&amp;org=apars&amp;doc=41D8B61D1E1C4FAB852567C9002C546C">IX74599</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/405">405</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7477.php">aix-digest(7477)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
</votes>
<comments>
<comment voter="Frech">XF:aix-digest(7477)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1488" seq="1999-1488">
<status>Entry</status>
<desc>sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-079a.shtml">I-079A</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/371">371</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7217.php">ibm-sdr-read-files(7217)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1489" seq="1999-1489">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/6384">19970304 Linux SuperProbe exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/364">364</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:xfree86-superprobe-testchip-bo(7198)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1490" seq="1999-1490">
<status>Entry</status>
<desc>xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926021&amp;w=2">19980528 ALERT: Tiresome security hole in &quot;xosview&quot;, RedHat5.1?</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926034&amp;w=2">19980529 Re: Tiresome security hole in &quot;xosview&quot; (xosexp.c)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/362">362</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/8787.php">linux-xosview-bo(8787)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1491" seq="1999-1491">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418994&amp;w=2">19960202 abuse Red Hat 2.1 security hole</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/354">354</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<noop count="1">Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1492" seq="1999-1492">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030">19980502-01-P3030</ref>
<ref source="XF" url="http://xforce.iss.net/static/2104.php">sgi-diskalign(2104)</ref>
<ref source="XF" url="http://xforce.iss.net/static/2103.php">sgi-diskperf(2103)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/348">348</ref>
</refs>
<votes>
<accept count="4">Cole, Foat, Frech, Stracener</accept>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1493" seq="1999-1493">
<status>Candidate</status>
<phase date="20020308">Modified</phase>
<desc>Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-23.html">CA-1991-23</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/34">34</ref>
<ref source="XF" url="http://xforce.iss.net/static/7158.php">apollo-crp-root-access(7158)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:apollo-crp-root-access(7158)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1494" seq="1999-1494">
<status>Entry</status>
<desc>colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/675">19940809 Re: IRIX 5.2 Security Advisory</ref>
<ref source="BUGTRAQ" url="http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html">19950307 sigh. another Irix 5.2 hole.</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P">19950209-00-P</ref>
<ref source="XF" url="http://xforce.iss.net/static/2112.php">sgi-colorview(2112)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/336">336</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1495" seq="1999-1495">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12580">19990218 xtvscreen and suse 6 </ref>
<ref source="XF" url="http://xforce.iss.net/static/1792.php">xtvscreen-overwrite(1792)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/325">325</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1496" seq="1999-1496">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14665">19990608 unneeded information in sudo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/321">321</ref>
<ref source="XF" url="http://xforce.iss.net/static/2277.php">sudo-file-exists(2277)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1497" seq="1999-1497">
<status>Candidate</status>
<phase date="20070122">Modified</phase>
<desc>Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39329">19991221 [w00giving '99 #11] IMail's password encryption scheme</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/880">880</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:imail-passwords(1901)
May be the same as CVE-2000-0019 on a different level of
abstraction.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1498" seq="1999-1498">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.</desc>
<refs>
<ref source="BUGTRAQ">19980406 insecure tmp file creation </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/82">82</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:linux-pkgtool-reply-symlink(7347) </comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1499" seq="1999-1499">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8966">19980410 BIND 4.9.7 named follows symlinks, clobbers anything</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/80">80</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Cole, Wall</noop>
<reject count="1">Foat</reject>
</votes>
<comments>
<comment voter="Foat">The files get written to /var/named which the user does not have write 
access.</comment>
<comment voter="Frech">XF:bind-sigint-sigiot-symlink(7366)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1500" seq="1999-1500">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internet Anywhere POP3 Mail Server 2.3.1 allows remote attackers to cause a denial of service (crash) via (1) LIST, (2) TOP, or (3) UIDL commands using letters as arguments.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93880357530599&amp;w=2">19991001 Vulnerabilities in the Internet Anywhere Mail Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/733">733</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:iams-pop3-command-dos(3283)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1501" seq="1999-1501">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89217373930054&amp;w=2">19980408 SGI O2 ipx security issue</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/70">70</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/71">71</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:irix-ipxchk-ipxlink-ifs-commands(7365)</comment>
<comment voter="Christey">DUPE CVE-1999-1040</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1502" seq="1999-1502">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89205623028934&amp;w=2">19980408 QuakeI client: serious holes.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/68">68</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/69">69</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:quake-precache-bo(7358)
XF:quake-server-address-bo(7359)
XF:quake-map-argument-bo(7360)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1503" seq="1999-1503">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Network Flight Recorder (NFR) 1.5 and 1.6 allows remote attackers to cause a denial of service in nfrd (crash) via a TCP packet with a null header and data field.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/63">63</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:nfr-tcp-packet-dos(7357)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1504" seq="1999-1504">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/8951">19980408 Re: AppleShare IP Mail Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/62">62</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:smtp-helo-bo(886)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1505" seq="1999-1505">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89200537415923&amp;w=2">19980407 QW vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/60">60</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:quakeworld-connect-bo(7356)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1506" seq="1999-1506">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-90.01.sun.sendmail.vulnerability">CA-1990-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/6">6</ref>
</refs>
<votes>
<accept count="3">Cole, Dik, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:sunos-sendmail-bin-access(7161)</comment>
<comment voter="Dik">sun bug 1028173</comment>
<comment voter="CHANGE">[Foat changed vote from ACCEPT to NOOP]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1507" seq="1999-1507">
<status>Entry</status>
<desc>Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-03.html">CA-1993-03</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/59">59</ref>
<ref source="XF" url="http://xforce.iss.net/static/521.php">sun-dir(521)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1508" seq="1999-1508">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286041430870&amp;w=2">19991116 [Fwd: Printer Vulnerability: Tektronix PhaserLink Webserver gives Administrator Password]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/806">806</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:tektronix-phaserlink-webserver-backdoor(6482)
Possible dupe with CVE-2001-0484 and BID-2659.</comment>
<comment voter="Christey">CVE-2001-0484 may be a duplicate.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1509" seq="1999-1509">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94177470915423&amp;w=2">19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94183041514522&amp;w=2">19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/773">773</ref>
<ref source="XF">eserv-fileread</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">Normalize XF:eserv-fileread(3449)
Normalize URL:http://xforce.iss.net/static/3449.php</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1510" seq="1999-1510">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92697301706956&amp;w=2">19990517 Vulnerabilities in BisonWare FTP Server 3.5</ref>
<ref source="XF" url="http://xforce.iss.net/static/3234.php">bisonware-command-bo(3234)</ref>
</refs>
<votes>
<accept count="3">Cole, Foat, Frech</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1511" seq="1999-1511">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94226003804744&amp;w=2">19991110 Multiples Remotes DoS Attacks in Artisoft XtraMail v1.11 Vulnerability </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/791">791</ref>
<ref source="XF" url="http://xforce.iss.net/static/3488.php">xtramail-pass-dos(3488)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1512" seq="1999-1512">
<status>Entry</status>
<desc>The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93219846414732&amp;w=2">19990716 AMaViS virus scanner for Linux - root exploit</ref>
<ref source="CONFIRM" url="http://www.amavis.org/ChangeLog.txt">http://www.amavis.org/ChangeLog.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/527">527</ref>
<ref source="XF" url="http://xforce.iss.net/static/2349.php">amavis-command-execute(2349)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1513" seq="1999-1513">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93616983223090&amp;w=2">19990830 One more 3Com SNMP vulnerability</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(ACCEPT; Task 2355)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1514" seq="1999-1514">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94130292519646&amp;w=2">19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94121377716133&amp;w=2">19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/749">749</ref>
<ref source="XF" url="http://xforce.iss.net/static/3401.php">expressfs-command-bo(3401)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">BugTraq reference date seems to be 19991029; see
http://online.securityfocus.com/archive/1/33123</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1515" seq="1999-1515">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/613">613</ref>
<ref source="XF" url="http://xforce.iss.net/static/3290.php">tfs-gateway-dos(3290)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1516" seq="1999-1516">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93677241318492&amp;w=2">19990902 [SECURITY] TenFour TFS SMTP 3.2 Buffer Overflow</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:tfs-gateway-dos(3290)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1517" seq="1999-1517">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>runtar in the Amanda backup system used in various UNIX operating systems executes tar with root privileges, which allows a user to overwrite or read arbitrary files by providing the target files to runtar.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94148942818975&amp;w=2">19991101 Amanda multiple vendor local root compromises</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/750">750</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:amanda-runtar(3402)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1518" seq="1999-1518">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93207728118694&amp;w=2">19990715 Shared memory DoS's</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/526">526</ref>
<ref source="XF" url="http://xforce.iss.net/static/2351.php">bsd-shared-memory-dos(2351)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1519" seq="1999-1519">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286244700573&amp;w=2">19991117 Remote D.o.S Attack in G6 FTP Server v2.0 (beta 4/5) Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/805">805</ref>
<ref source="XF" url="http://xforce.iss.net/static/3513.php">g6ftp-username-dos(3513)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1520" seq="1999-1520">
<status>Entry</status>
<desc>A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92647407227303&amp;w=2">19990511 [ALERT] Site Server 3.0 May Expose SQL IDs and PSWs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/256">256</ref>
<ref source="XF" url="http://xforce.iss.net/static/2270.php">siteserver-site-csc(2270)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1521" seq="1999-1521">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93720402717560&amp;w=2">19990912 Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94121824921783&amp;w=2">19990729 Vulnerability in CMail SMTP Server Version 2.4: Remotely exploitable buffer</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/633">633</ref>
<ref source="XF" url="http://xforce.iss.net/static/2240.php">cmail-command-bo(2240)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="4">Christey, Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Christey">Remove &quot;attack&quot; from description and slightly rewrite.</comment>
<comment voter="Christey">ADDREF BUGTRAQ:19991029 Vulnerability in CMail SMTP Server Version 2.4: Remotely exploitable buffer
URL:URL:http://www.securityfocus.com/archive/1/32573 
ADDREF BUGTRAQ:19990616 C-Mail SMTP Server Remote Buffer Overflow Exploit
URL:http://online.securityfocus.com/archive/1/15524

Note: this last post exploits an overflow through VRFY
instead of MAIL FROM.  However, CD:SF-LOC suggests merging two
issues of the same type that are in the same versions.

ADDREF BUGTRAQ:19990526 Multiple Web Interface Security Holes
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92774425211457&amp;w=2</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1522" seq="1999-1522">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Vulnerability in htmlparse.pike in Roxen Web Server 1.3.11 and earlier, possibly related to recursive parsing and referer tags in RXML.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942579008408&amp;w=2">19991007 Roxen security alert</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:roxen-rxml-recursive-parsing(3372)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1523" seq="1999-1523">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93901161727373&amp;w=2">19991004 </ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93941351229256&amp;w=2">19991006 Re: Sample DOS against the Sambar HTTP-Server</ref>
<ref source="XF" url="http://xforce.iss.net/static/1672.php">sambar-logging-bo(1672)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1524" seq="1999-1524">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93424680430460&amp;w=2">19990807 Re: FlowPoint DSL router vulnerability </ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1525" seq="1999-1525">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420670&amp;w=2">19970314 Shockwave Security Alert</ref>
<ref source="XF" url="http://xforce.iss.net/static/1585.php">shockwave-internal-access(1585)</ref>
<ref source="XF" url="http://xforce.iss.net/static/1586.php">shockwave-file-read-vuln(1586)</ref>
<ref source="XF" url="http://xforce.iss.net/static/460.php">http-ns-shockwave(460)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1526" seq="1999-1526">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12842">19990311 [Fwd: Shockwave 7 Security Hole]</ref>
<ref source="XF" url="http://xforce.iss.net/static/1931.php">shockwave-updater(1931)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1527" seq="1999-1527">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94338883114254&amp;w=2">19991123 NetBeans/ Forte' Java IDE HTTP vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/816">816</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:sun-java-ide-http-access(8333)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1528" seq="1999-1528">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94261444428430&amp;w=2">19991114 MacOS 9 and the MacOS Netware Client</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/794">794</ref>
</refs>
<votes>
<accept count="1">Cole</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:macos-netware-nds-access(8339)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1529" seq="1999-1529">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94201512111092&amp;w=2">19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94199707625818&amp;w=2">19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94210427406568&amp;w=2">19991108 Re: Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94204166130782&amp;w=2">19991108 Patch for VirusWall 3.23.</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94208143007829&amp;w=2">19991108 Patch for VirusWall 3.23.</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/55551">20000417 New DOS on Interscan NT/3.32</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/787">787</ref>
<ref source="XF" url="http://xforce.iss.net/static/3465.php">viruswall-helo-bo(3465)</ref>
</refs>
<votes>
<accept count="2">Cole, Foat</accept>
<noop count="1">Wall</noop>
<reject count="1">Frech</reject>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1530" seq="1999-1530">
<status>Entry</status>
<desc>cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94209954200450&amp;w=2">19991108 Security flaw in Cobalt RaQ2 cgiwrap</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225629200045&amp;w=2">19991109 [Cobalt] Security Advisory - cgiwrap</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/777">777</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7764.php">cobalt-cgiwrap-incorrect-permissions(7764)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/35">35</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1531" seq="1999-1531">
<status>Entry</status>
<desc>Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/763">763</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7767.php">ibm-homepageprint-bo(7767)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1532" seq="1999-1532">
<status>Candidate</status>
<phase date="20011126">Modified</phase>
<desc>Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94117465014255&amp;w=2">19991029 message:Netscape Messaging Server RCPT TO vul.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/748">748</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:netscape-messaging-rcptto-dos(8340)
Description ends with a comma and not a period, possibly 
indicating that the sentence is not complete,</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1533" seq="1999-1533">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93846522511387&amp;w=2">19990926 DoS Exploit in Eicon Diehl LAN ISDN Modem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/665">665</ref>
<ref source="XF" url="http://xforce.iss.net/static/3317.php">diva-lan-isdn-dos(3317)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1534" seq="1999-1534">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837184228248&amp;w=2">19990923 Multiple vendor Knox Arkiea local root/remote DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/661">661</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:arkiea-backup-home-bo(3322)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1535" seq="1999-1535">
<status>Entry</status>
<desc>Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93256878011447&amp;w=2">19990720 Buffer overflow in AspUpload 1.4</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93501427820328&amp;w=2">19990818 AspUpload Buffer Overflow Fixed</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/592">592</ref>
<ref source="XF" url="http://xforce.iss.net/static/3291.php">http-aspupload-bo(3291)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1536" seq="1999-1536">
<status>Candidate</status>
<phase date="20070207">Modified</phase>
<desc>.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93347785827287&amp;w=2">19990730 World writable root owned script in SalesBuilder (RedHat 6.0)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/560">560</ref>
<ref source="OSVDB" url="http://www.osvdb.org/13557">13557</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(ACCEPT; Task 2356)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1537" seq="1999-1537">
<status>Entry</status>
<desc>IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827329577&amp;w=2">19990707 SSL and IIS.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/521">521</ref>
<ref source="XF" url="http://xforce.iss.net/static/2352.php">ssl-iis-dos(2352)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1538" seq="1999-1538">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91638375309890&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91632724913080&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/189">189</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
<comment voter="Frech">XF:iis-ismdll-info(7566)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1539" seq="1999-1539">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225924803704&amp;w=2">19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94223972910670&amp;w=2">19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/796">796</ref>
<ref source="XF" url="http://xforce.iss.net/static/3491.php">qvtterm-login-dos(3491)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1540" seq="1999-1540">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code.</desc>
<refs>
<ref source="L0PHT" url="http://www.atstake.com/research/advisories/1999/shell-lock.txt">19991004</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93916168802365&amp;w=2">19991005 Cactus Software's shell-lock</ref>
<ref source="XF" url="http://xforce.iss.net/static/3356.php">cactus-shell-lock-retrieve-shell-code(3356)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1541" seq="1999-1541">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>shell-lock in Cactus Software Shell Lock allows local users to read or modify decoded shell files before they are executed, via a symlink attack on a temporary file.</desc>
<refs>
<ref source="L0PHT" url="http://www.atstake.com/research/advisories/1999/shell-lock.txt">19991004</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93916168802365&amp;w=2">19991005 Cactus Software's shell-lock</ref>
<ref source="XF" url="http://xforce.iss.net/static/3358.php">cactus-shell-lock-root-privs(3358)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-1542" seq="1999-1542">
<status>Entry</status>
<desc>RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the &quot;MAIL FROM&quot; command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915641729415&amp;w=2">19991004 RH6.0 local/remote command execution</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923853105687&amp;w=2">19991006 Fwd: [Re: RH6.0 local/remote command execution]</ref>
<ref source="XF" url="http://xforce.iss.net/static/3353.php">linux-rh-rpmmail(3353)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1543" seq="1999-1543">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>MacOS uses weak encryption for passwords that are stored in the Users &amp; Groups Data File.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93188174906513&amp;w=2">19990710 MacOS system encryption algorithm</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93736667813924&amp;w=2">19990914 MacOS system encryption algorithm 3</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/519">519</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(ACCEPT; Task 2357)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1544" seq="1999-1544">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91722115016183&amp;w=2">19990124 Advisory: IIS FTP Exploit/DoS Attack</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<noop count="2">Cole, Foat</noop>
<reject count="1">Frech</reject>
</votes>
<comments>
<comment voter="Frech">Dupe CVE-1999-0349</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1545" seq="1999-1545">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93216103027827&amp;w=2">19990714 </ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93226771401036&amp;w=2">19990717 joe 2.8 makes world-readable DEADJOE</ref>
</refs>
<votes>
<noop count="3">Cole, Foat, Wall</noop>
<reviewing count="1">Frech</reviewing>
</votes>
<comments>
<comment voter="Frech">(ACCEPT; Task 2358)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1546" seq="1999-1546">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12217">19990129 TROJAN: netstation.navio-comm.rte 1.1.0.1</ref>
<ref source="XF" url="http://xforce.iss.net/static/1724.php">navionc-config-script(1724)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1547" seq="1999-1547">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94359982417686&amp;w=2">19991125 Oracle Web Listener</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94390053530890&amp;w=2">19991125 Oracle Web Listener</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/841">841</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:oracle-weblistener-bypass-restrictions(8355)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1548" seq="1999-1548">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.</desc>
<refs>
<ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_Cabletron.html">19991124 Cabletron SmartSwitch Router 8000 Firmware v2.x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/841">821</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:smartswitch-arp-flood-dos(7770)
BID URL should be 821, not 841.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1549" seq="1999-1549">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a &quot;secure&quot; hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286509804526&amp;w=2">19991116 lynx 2.8.x - 'special URLs' anti-spoofing protection is weak</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/804">804</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:lynx-lynxurl-spoof(8342)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1550" seq="1999-1550">
<status>Entry</status>
<desc>bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the &quot;file&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217006208374&amp;w=2">19991108 BigIP - bigconf.cgi holes</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217879020184&amp;w=2">19991109 Re: BigIP - bigconf.cgi holes </ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225879703021&amp;w=2">19991109 </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/778">778</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7771.php">bigip-bigconf-view-files(7771)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1551" seq="1999-1551">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990302 Multiple IMail Vulnerabilites</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/505">505</ref>
<ref source="XF" url="http://xforce.iss.net/static/1898.php">imail-websvc-overflow(1898)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1552" seq="1999-1552">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://lists.insecure.org/lists/bugtraq/1994/Jul/0038.html">19940720 xnews and XDM</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/358">358</ref>
</refs>
<votes>
<noop count="2">Cole, Foat</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1553" seq="1999-1553">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12730">19990301 [0z0n3] XCmail remotely exploitable vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/311">311</ref>
<ref source="XF" url="http://xforce.iss.net/static/1859.php">xcmail-reply-overflow(1859)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1554" seq="1999-1554">
<status>Candidate</status>
<phase date="20020218">Modified</phase>
<desc>/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-08.html">CA-1990-08</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/13">13</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3164.php">sgi-irix-reset(3164)</ref>
</refs>
<votes>
<accept count="2">Cole, Stracener</accept>
<modify count="1">Frech</modify>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">XF:sgi-irix-reset(3164)</comment>
<comment voter="CHANGE">[Foat changed vote from ACCEPT to NOOP]</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-1555" seq="1999-1555">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with &quot;EVERYONE FULL CONTROL&quot; permissions, which allows local users to cause Inoculan's antivirus update feature to install a Trojan horse dll.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9515">19980611 Cheyenne Inoculan vulnerability on NT</ref>
<ref source="BID">106</ref>
<ref source="XF" url="http://xforce.iss.net/static/1536.php">inoculan-bad-permissions(1536)</ref>
</refs>
<votes>
<accept count="1">Frech</accept>
<noop count="3">Cole, Foat, Wall</noop>
</votes>
<comments>
<comment voter="Frech">http://support.cai.com/Download/patches/inocnt.html</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-1556" seq="1999-1556">
<status>Entry</status>
<desc>Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222453431645&amp;w=2">19980629 MS SQL Server 6.5 stores password in unprotected registry keys</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/109">109</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7354">mssql-sqlexecutivecmdexec-password(7354)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-1557" seq="1999-1557">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990301 Multiple IMail Vulnerabilites</ref>
<ref source="XF" url="http://xforce.iss.net/static/1895.php">imail-imap-overflow(1895)</ref>
</refs>
<votes>
<accept count="2">Cole, Frech</accept>
<noop count="2">Foat, Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CAN" name="CVE-1999-1558" seq="1999-1558">
<status