CVE List

Id CVE No. Status Description Phase Votes Comments Actions
546  CVE-1999-0560  Candidate  A system-critical Windows NT file or directory has inappropriate permissions.  Proposed (19990803)  ACCEPT(2) Baker, Wall | RECAST(1) Northcutt  Northcutt> I think we should specify these  View
547  CVE-1999-0561  Candidate  IIS has the #exec function enabled for Server Side Include (SSI) files.  Proposed (19990728)  NOOP(2) Baker, Northcutt | RECAST(1) Shostack | REJECT(1) LeBlanc  LeBlanc> Does not meet definition of a vulnerability. This function is | just enabled. You can turn it off if you want. if you trust the people | putting up your web pages, this isn"t a problem. If you don"t, this is | just one of many things you need to change.  View
548  CVE-1999-0562  Candidate  The registry in Windows NT can be accessed remotely by users who are not administrators.  Modified (20061101)  ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | RECAST(1) Northcutt  Northcutt> This isn"t all or nothing, users may be allowed to access part of the | registry. | Frech> XF:nt-winreg-all | XF:nt-winreg-net  View
549  CVE-1999-0564  Candidate  An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn"t require a password) or to become disabled.  Proposed (19990728)  ACCEPT(2) Baker, Shostack | NOOP(1) Northcutt    View
550  CVE-1999-0565  Candidate  A Sendmail alias allows input to be piped to a program.  Proposed (19990728)  ACCEPT(1) Northcutt | NOOP(1) Baker | RECAST(1) Shostack | REVIEWING(1) Christey  Shostack> Is this a default alias? Is my .procmailrc an instance of this? | Christey> It is not entirely clear whether the simple fact that an alias | pipes into a program should be considered a vulnerability. It | all depends on the behavior of that particular program. This | is one of a number of configuration-related issues from the | "draft" CVE that came from vulnerability scanners. In | general, when we get to general configuration and "policy," | it becomes more difficult to use the current CVE model to | represent them. So at the very least, this candidate (and | similar ones) should be given close consideration and | discussion before being added to the official CVE list. | | Because this candidate is related to general configuration | issues, and we have not completely determined how to handle | such issues in CVE, this candidate cannot be promoted to an | official CVE entry until such issues are resolved.  View

Page 110 of 20943, showing 5 records out of 104715 total, starting on record 546, ending on 550

Actions