CVE List

Id CVE No. Status Description Phase Votes Comments Actions
561  CVE-1999-0579  Candidate  A Windows NT system"s registry audit policy does not log an event success or failure for non-critical registry keys.  Proposed (19990721)  ACCEPT(3) Baker, Shostack, Wall | MODIFY(2) Frech, Ozancin | REJECT(1) Northcutt  Ozancin> Again only failure may be of interest. It would be impractical to wad | through the incredibly large amount of logging that this would generate. It | could overwhelm log entries that you might find interesting. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-object-audit(228)  View
562  CVE-1999-0580  Candidate  The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.  Proposed (19990803)  ACCEPT(1) Wall | NOOP(1) Baker | RECAST(1) Northcutt  Northcutt> I think we can define appropriate, take a look at the nt security .pdf | and see if you can"t see a way to phrase specific keys in a way that | defines inappropriate. | Baker> This is way vague...  View
563  CVE-1999-0581  Candidate  The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.  Proposed (19990803)  ACCEPT(1) Wall | NOOP(1) Baker | RECAST(1) Northcutt  Northcutt> I think we can define appropriate, take a look at the nt security .pdf | and see if you can"t see a way to phrase specific keys in a way that | defines inappropriate. | Baker> way too vague  View
564  CVE-1999-0582  Candidate  A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.  Proposed (19990721)  ACCEPT(3) Ozancin, Shostack, Wall | MODIFY(2) Baker, Frech | REJECT(1) Northcutt  Northcutt> The definition is? | Baker> Maybe a rewording of this one too. I think most people would agree on | some "minimum" policies like 3-5 bad attempts lockout for an hour or | until the administrator unlocks the account. | Suggested rewrite - | A Windows NT account policy does not enforce reasonable minimum | security-critical settings for lockouts, e.g. lockout duration, | lockout after bad logon attempts, etc. | Ozancin> with reservations | What is appropriate? | Frech> XF:nt-thres-lockout | XF:nt-lock-duration | XF:nt-lock-window | XF:nt-perm-lockout | XF:lockout-disabled  View
565  CVE-1999-0583  Candidate  There is a one-way or two-way trust relationship between Windows NT domains.  Proposed (19990728)  NOOP(2) Baker, Christey | REJECT(2) Northcutt, Shostack  Christey> XF:nt-trusted-domain(1284)  View

Page 113 of 20943, showing 5 records out of 104715 total, starting on record 561, ending on 565

Actions