CVE List

Id CVE No. Status Description Phase Votes Comments Actions
556  CVE-1999-0572  Candidate  .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.  Modified (20041017)  ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | NOOP(2) Christey, Northcutt  Northcutt> I don"t quite get what this means, sorry | Frech> XF:nt-regfile(178) | Christey> MISC:http://security-archive.merton.ox.ac.uk/nt-security-199902/0087.html  View
557  CVE-1999-0575  Candidate  A Windows NT system"s user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.  Proposed (19990721)  ACCEPT(4) Christey, Ozancin, Shostack, Wall | MODIFY(1) Frech | RECAST(2) Baker, Northcutt  Northcutt> It isn"t a great truth that you should enable all or the above, if you | do you potentially introduce a vulnerbility of filling up the file | system with stuff you will never look at. | Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Christey> The list of event types is very useful for lookup. | Frech> XF:nt-system-audit | XF:nt-logon-audit | XF:nt-object-audit | XF:nt-privil-audit | XF:nt-process-audit | XF:nt-policy-audit | XF:nt-account-audit | CHANGE> [Baker changed vote from REVIEWING to RECAST]  View
558  CVE-1999-0576  Candidate  A Windows NT system"s file audit policy does not log an event success or failure for security-critical files or directories.  Proposed (19990721)  ACCEPT(3) Baker, Shostack, Wall | MODIFY(2) Frech, Ozancin | REJECT(1) Northcutt  Northcutt> 1.) Too general are we ready to state what the security-critical files | and directories are | 2.) Does Ataris, Windows CE, PalmOS, Linux have such a capability | Ozancin> Some files and directories are clearly understood to be critical. Others are | unclear. We need to clarify that critical is. | Frech> XF:nt-object-audit  View
559  CVE-1999-0577  Candidate  A Windows NT system"s file audit policy does not log an event success or failure for non-critical files or directories.  Proposed (19990721)  ACCEPT(2) Shostack, Wall | MODIFY(3) Baker, Frech, Ozancin | REJECT(1) Northcutt  Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Perhaps only failure should be logged. | Frech> XF:nt-object-audit | CHANGE> [Baker changed vote from REVIEWING to MODIFY] | Baker> Failure on non-critical files is what should be monitored.  View
560  CVE-1999-0578  Candidate  A Windows NT system"s registry audit policy does not log an event success or failure for security-critical registry keys.  Proposed (19990721)  ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) Northcutt  Ozancin> with reservation | Again what is defined as critical | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-object-audit(228)  View

Page 112 of 20943, showing 5 records out of 104715 total, starting on record 556, ending on 560

Actions