CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1700 | CVE-2000-0122 | Candidate | Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program. | Modified (20070607) | ACCEPT(4) Baker, Cole, LeBlanc, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:ms-frontpage-get-htimage | Christey> It appears that this was rediscovered in April 18, 2000: | BUGTRAQ:20000418 More vulnerabilities in FP | URL:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38FCAC0C.869611C0%40hobbiton.org | | This in turn may match BID:1141 | Christey> According to Scott Culp of Microsoft, this was patched in MS:MS00-028. | Christey> BID:1141 ?? | View |
1704 | CVE-2000-0126 | Candidate | Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack. | Proposed (20000208) | ACCEPT(4) Baker, Cole, LeBlanc, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:iis-dir-traversal-read | Christey> This may be a variant of CVE-2000-0097 or CVE-2000-0098. | MS:MS00-006 says that a new variant was announced on February 4, | but that it only revealed the physical path. The post related | to this CAN is dated February 2, but it describes the impact | as being able to read files. | | See http://marc.theaimsgroup.com/?l=bugtraq&m=94972759912790&w=2 | Christey> According to Mark Burnett: "CISADV000202 [described] idq.dll | and involving .idq files... IDQ files are vulnerable to a | double-dot bug that allows files on the same partition as the | web root to be viewed.... [This candidate] refers to the same | MS00-006" | | ADDREF MS:MS00-006 | ADDREF BID:968 ? | Frech> Change iis-dir-traversal-read(4014) to http-indexserver-view-files(4232) | View |
1878 | CVE-2000-0300 | Candidate | The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts. | Proposed (20000426) | ACCEPT(4) Baker, Cole, Levy, Prosser | MODIFY(1) Frech | REVIEWING(1) Wall | Frech> XF:pcanywhere-weak-encryption | Prosser> http://service2.symantec.com/SUPPORT/pca.nsf/pfdocs/1999022312571812 | Upgraded in pcA 10 | View |
1834 | CVE-2000-0256 | Candidate | Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability. | Modified (20070607) | ACCEPT(4) Baker, Cole, Levy, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:frontpage-ext-image-map | Christey> Possibly related to BUGTRAQ:20000418 More vulnerabilities in FP | http://archives.neohapsis.com/archives/bugtraq/2000-04/0116.html | View |
1837 | CVE-2000-0259 | Candidate | The default permissions for the CryptographyOffload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users. | Proposed (20000426) | ACCEPT(4) Baker, Cole, Levy, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:winnt-cryptkeys-compromise | Christey> Include "CryptoAPI" to facilitate search. | MSKB:Q259496 | URL:http://www.microsoft.com/technet/support/kb.asp?ID=259496 | View |
Page 1027 of 20943, showing 5 records out of 104715 total, starting on record 5131, ending on 5135