CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1700  CVE-2000-0122  Candidate  Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program.  Modified (20070607)  ACCEPT(4) Baker, Cole, LeBlanc, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:ms-frontpage-get-htimage | Christey> It appears that this was rediscovered in April 18, 2000: | BUGTRAQ:20000418 More vulnerabilities in FP | URL:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38FCAC0C.869611C0%40hobbiton.org | | This in turn may match BID:1141 | Christey> According to Scott Culp of Microsoft, this was patched in MS:MS00-028. | Christey> BID:1141 ??  View
1704  CVE-2000-0126  Candidate  Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.  Proposed (20000208)  ACCEPT(4) Baker, Cole, LeBlanc, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:iis-dir-traversal-read | Christey> This may be a variant of CVE-2000-0097 or CVE-2000-0098. | MS:MS00-006 says that a new variant was announced on February 4, | but that it only revealed the physical path. The post related | to this CAN is dated February 2, but it describes the impact | as being able to read files. | | See http://marc.theaimsgroup.com/?l=bugtraq&m=94972759912790&w=2 | Christey> According to Mark Burnett: "CISADV000202 [described] idq.dll | and involving .idq files... IDQ files are vulnerable to a | double-dot bug that allows files on the same partition as the | web root to be viewed.... [This candidate] refers to the same | MS00-006" | | ADDREF MS:MS00-006 | ADDREF BID:968 ? | Frech> Change iis-dir-traversal-read(4014) to http-indexserver-view-files(4232)  View
1878  CVE-2000-0300  Candidate  The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.  Proposed (20000426)  ACCEPT(4) Baker, Cole, Levy, Prosser | MODIFY(1) Frech | REVIEWING(1) Wall  Frech> XF:pcanywhere-weak-encryption | Prosser> http://service2.symantec.com/SUPPORT/pca.nsf/pfdocs/1999022312571812 | Upgraded in pcA 10  View
1834  CVE-2000-0256  Candidate  Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.  Modified (20070607)  ACCEPT(4) Baker, Cole, Levy, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:frontpage-ext-image-map | Christey> Possibly related to BUGTRAQ:20000418 More vulnerabilities in FP | http://archives.neohapsis.com/archives/bugtraq/2000-04/0116.html  View
1837  CVE-2000-0259  Candidate  The default permissions for the CryptographyOffload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.  Proposed (20000426)  ACCEPT(4) Baker, Cole, Levy, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:winnt-cryptkeys-compromise | Christey> Include "CryptoAPI" to facilitate search. | MSKB:Q259496 | URL:http://www.microsoft.com/technet/support/kb.asp?ID=259496  View

Page 1027 of 20943, showing 5 records out of 104715 total, starting on record 5131, ending on 5135

Actions