CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1903  CVE-2000-0325  Candidate  The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.  Modified (20020222-01)  ACCEPT(5) Armstrong, Baker, Cole, Prosser, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc | REVIEWING(1) Christey  LeBlanc> - same as CVE-1999-1011 | If I"m misunderstanding something here, please correct me. In fact, it has | the same bulletin as a reference. | Frech> XF:jet-vba-shell | Prosser> This entry is not the same as "now" CVE-1999-1011. That entry is "The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands." This one should be correct. | Christey> BUGTRAQ:19990525 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=bugtraq&m=92765973107637&w=2 | NTBUGTRAQ:19990526 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=ntbugtraq&m=92781907215748&w=2 | Christey> The Microsoft advisory itself describes two separate | vulnerabilities, calling the TEXT I-ISAM problem | (CVE-2000-0323) a variant of the VBA Shell problem (this | CAN). In addition, CVE-2000-0323 does *not* appear in Jet | 4.0, while this one does. Since one problem appears in a | different version than the other, CD:SF-LOC suggests keeping | these candidates SPLIT. | | BID:548 | http://www.securityfocus.com/bid/548 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Need to clarify whether the Bugtraq/NTBugtraq posts are | really describing the same issue (those are BID:286).  View
3911  CVE-2001-1107  Candidate  SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server.  Proposed (20020315)  ACCEPT(5) Armstrong, Baker, Frech, Green, Ziese | NOOP(3) Cole, Foat, Wall    View
3171  CVE-2001-0350  Candidate  Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.  Modified (20050509)  ACCEPT(5) Armstrong, Balinsky, Cole, Foat, Ziese | MODIFY(1) Frech | RECAST(1) Stracener | REVIEWING(2) Christey, Wall  Wall> Perhaps merge 0349 and 0350 unless there is a bigger difference. | Stracener> Merge this with 0349. | Frech> XF:win2k-telnet-pipe-privileges(6664) | Christey> CIAC:L-092 | URL:http://www.ciac.org/ciac/bulletins/l-092.shtml | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CERT-VN:VU#587587 | URL:http://www.kb.cert.org/vuls/id/587587 | BID:2849 | Microsoft identifies two separate vulnerabilities that are extremely | similar, but the security bulletin states that "The two | vulnerabilities differ primarily in the way they exploit the | underlying problem regarding named pipe creation." So, it may be | necessary to merge CVE-2001-0350 with CVE-2001-0349. | | If one issue is because of predictable names, and another | issue is because pipe ownership isn"t properly verified, then | these could stay SPLIT, and the descriptions should be | modified accordingly.  View
4557  CVE-2002-0164  Candidate  Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges.  Modified (20100521)  ACCEPT(5) Armstrong, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(2) Christey, Foat  Christey> SGI:20021001-01-P | Christey> BUGTRAQ:20021024 GLSA: xfree | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103547625009363&w=2 | | This Gentoo advisory mentions XFree86 4.2.0-r12 and earlier. | Frech> XF:xfree86-mitshm-memory-access(8706) | Christey> REDHAT:RHSA-2003:067 | URL:http://www.redhat.com/support/errata/RHSA-2003-067.html | Christey> Add something like "Xfree86 before 4.2.1" to the description. | | The affected versions aren"t quite clear, as various vendor | advisories list different versions. | Christey> DEBIAN:DSA-380 | Christey> CALDERA:CSSA-2003-SCO.26  View
1335  CVE-1999-1355  Candidate  BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.  Proposed (20010912)  ACCEPT(5) Armstrong, Cole, Foat, Frech, Stracener | NOOP(1) Wall    View

Page 1063 of 20943, showing 5 records out of 104715 total, starting on record 5311, ending on 5315

Actions