CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4495 | CVE-2002-0101 | Candidate | Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released. | Proposed (20020315) | ACCEPT(4) Foat, Frech, Green, Ziese | NOOP(1) Cole | REVIEWING(1) Wall | Ziese> would seem appropriate as a CVE entry. | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
154 | CVE-1999-0154 | Candidate | IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. | Proposed (20010912) | ACCEPT(4) Foat, Frech, Stracener, Wall | NOOP(3) Baker, Christey, Cole | Christey> This is the precursor to the problem that is identified in | CVE-1999-0253. | Christey> CIAC:H-48 | URL:http://ciac.llnl.gov/ciac/bulletins/h-48.shtml | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
245 | CVE-1999-0246 | Candidate | HP Remote Watch allows a remote user to gain root access. | Proposed (19990630) | ACCEPT(4) Frech, Hill, Northcutt, Prosser | NOOP(1) Baker | RECAST(1) Christey | Frech> Comment: Determine if it"s RemoteWatch or Remote Watch. | Christey> HP:HPSBUX9610-039 alludes to multiple vulnerabilities in | Remote Watch (the advisory uses two words, not one, for the | "Remote Watch" name) | | ADDREF BUGTRAQ:19961015 HP/UX Remote Watch (was Re: BoS: SOD remote exploit) | URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=199610151351.JAA18241@grymoire.crd.ge.com | Prosser> agree that the advisory mentions two vulnerabilities in Remote | Watch, one being a socket connection and other with the showdisk utility | which seems to be a suid vulnerability. Never get much details on this | anywhere since the recommendation is to remove the program since it is | obsolete and superceded by later tools. Believe the biggest concern here is | to just not run the tool at all. | Christey> CIAC:H-16 | Also, http://www.cert.org/vendor_bulletins/VB-96.20.hp | And possibly AUSCERT:AA-96.07 at | ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.07.HP-UX.Remote.Watch.vul | Christey> Also BUGTRAQ:19961013 BoS: SOD remote exploit | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419969&w=2 | Include "remwatch" in the description to facilitate search. | View |
756 | CVE-1999-0776 | Candidate | Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack. | Proposed (19991214) | ACCEPT(4) Frech, Levy, Ozancin, Stracener | MODIFY(1) Baker | NOOP(6) Armstrong, Blake, Cole, Landfield, LeBlanc, Wall | REVIEWING(1) Christey | Christey> This candidate is unconfirmed by the vendor. | | Posted by Arne Vidstrom. | Blake> I"d like to change my vote on this from ACCEPT to NOOP. I did some | digging and the vendor seems to have discontinued the product, so no | information is available beyond Arne"s post. Unless Andre has a copy | in his archive and can test it, I think we have to leave it out. | Wall> I agree with Blake. We have not seen the product and it has been discontinued. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> If this is (or was) tested by some tool, we should ACCEPT it. | Baker> http://www.securityfocus.com/bid/270 | Christey> BID:270 | URL:http://www.securityfocus.com/bid/270 | View |
1978 | CVE-2000-0400 | Candidate | The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user"s system by encoding it within an email message or news post. | Proposed (20000615) | ACCEPT(4) Frech, Levy, Ozancin, Wall | NOOP(2) Cole, Stracener | REJECT(1) Christey | REVIEWING(1) LeBlanc | LeBlanc> COMMENT - this definately will not work if the user has applied the security | patch. I don"t know whether this repros right now, and have sent a query to | find out. | Christey> Is this now documented in MS:MS00-042? | LeBlanc> the problem isn"t in the Active Movie control. What was | observed was a symptom of another problem that got fixed in | some bulletin or another - I don"t remember. | Christey> According to Scott Culp, this existed because | the patch for the Cache Bypass vulnerability (MS:MS00-046, | CVE-2000-0621) was not applied, so this should be REJECTed | as a duplicate of CVE-2000-0621. | View |
Page 1049 of 20943, showing 5 records out of 104715 total, starting on record 5241, ending on 5245