CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4495  CVE-2002-0101  Candidate  Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.  Proposed (20020315)  ACCEPT(4) Foat, Frech, Green, Ziese | NOOP(1) Cole | REVIEWING(1) Wall  Ziese> would seem appropriate as a CVE entry. | CHANGE> [Foat changed vote from NOOP to ACCEPT]  View
154  CVE-1999-0154  Candidate  IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.  Proposed (20010912)  ACCEPT(4) Foat, Frech, Stracener, Wall | NOOP(3) Baker, Christey, Cole  Christey> This is the precursor to the problem that is identified in | CVE-1999-0253. | Christey> CIAC:H-48 | URL:http://ciac.llnl.gov/ciac/bulletins/h-48.shtml | CHANGE> [Foat changed vote from NOOP to ACCEPT]  View
245  CVE-1999-0246  Candidate  HP Remote Watch allows a remote user to gain root access.  Proposed (19990630)  ACCEPT(4) Frech, Hill, Northcutt, Prosser | NOOP(1) Baker | RECAST(1) Christey  Frech> Comment: Determine if it"s RemoteWatch or Remote Watch. | Christey> HP:HPSBUX9610-039 alludes to multiple vulnerabilities in | Remote Watch (the advisory uses two words, not one, for the | "Remote Watch" name) | | ADDREF BUGTRAQ:19961015 HP/UX Remote Watch (was Re: BoS: SOD remote exploit) | URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=199610151351.JAA18241@grymoire.crd.ge.com | Prosser> agree that the advisory mentions two vulnerabilities in Remote | Watch, one being a socket connection and other with the showdisk utility | which seems to be a suid vulnerability. Never get much details on this | anywhere since the recommendation is to remove the program since it is | obsolete and superceded by later tools. Believe the biggest concern here is | to just not run the tool at all. | Christey> CIAC:H-16 | Also, http://www.cert.org/vendor_bulletins/VB-96.20.hp | And possibly AUSCERT:AA-96.07 at | ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.07.HP-UX.Remote.Watch.vul | Christey> Also BUGTRAQ:19961013 BoS: SOD remote exploit | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419969&w=2 | Include "remwatch" in the description to facilitate search.  View
756  CVE-1999-0776  Candidate  Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.  Proposed (19991214)  ACCEPT(4) Frech, Levy, Ozancin, Stracener | MODIFY(1) Baker | NOOP(6) Armstrong, Blake, Cole, Landfield, LeBlanc, Wall | REVIEWING(1) Christey  Christey> This candidate is unconfirmed by the vendor. | | Posted by Arne Vidstrom. | Blake> I"d like to change my vote on this from ACCEPT to NOOP. I did some | digging and the vendor seems to have discontinued the product, so no | information is available beyond Arne"s post. Unless Andre has a copy | in his archive and can test it, I think we have to leave it out. | Wall> I agree with Blake. We have not seen the product and it has been discontinued. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> If this is (or was) tested by some tool, we should ACCEPT it. | Baker> http://www.securityfocus.com/bid/270 | Christey> BID:270 | URL:http://www.securityfocus.com/bid/270  View
1978  CVE-2000-0400  Candidate  The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user"s system by encoding it within an email message or news post.  Proposed (20000615)  ACCEPT(4) Frech, Levy, Ozancin, Wall | NOOP(2) Cole, Stracener | REJECT(1) Christey | REVIEWING(1) LeBlanc  LeBlanc> COMMENT - this definately will not work if the user has applied the security | patch. I don"t know whether this repros right now, and have sent a query to | find out. | Christey> Is this now documented in MS:MS00-042? | LeBlanc> the problem isn"t in the Active Movie control. What was | observed was a symptom of another problem that got fixed in | some bulletin or another - I don"t remember. | Christey> According to Scott Culp, this existed because | the patch for the Cache Bypass vulnerability (MS:MS00-046, | CVE-2000-0621) was not applied, so this should be REJECTed | as a duplicate of CVE-2000-0621.  View

Page 1049 of 20943, showing 5 records out of 104715 total, starting on record 5241, ending on 5245

Actions