CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
561 | CVE-1999-0579 | Candidate | A Windows NT system"s registry audit policy does not log an event success or failure for non-critical registry keys. | Proposed (19990721) | ACCEPT(3) Baker, Shostack, Wall | MODIFY(2) Frech, Ozancin | REJECT(1) Northcutt | Ozancin> Again only failure may be of interest. It would be impractical to wad | through the incredibly large amount of logging that this would generate. It | could overwhelm log entries that you might find interesting. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-object-audit(228) | View |
562 | CVE-1999-0580 | Candidate | The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions. | Proposed (19990803) | ACCEPT(1) Wall | NOOP(1) Baker | RECAST(1) Northcutt | Northcutt> I think we can define appropriate, take a look at the nt security .pdf | and see if you can"t see a way to phrase specific keys in a way that | defines inappropriate. | Baker> This is way vague... | View |
563 | CVE-1999-0581 | Candidate | The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. | Proposed (19990803) | ACCEPT(1) Wall | NOOP(1) Baker | RECAST(1) Northcutt | Northcutt> I think we can define appropriate, take a look at the nt security .pdf | and see if you can"t see a way to phrase specific keys in a way that | defines inappropriate. | Baker> way too vague | View |
564 | CVE-1999-0582 | Candidate | A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. | Proposed (19990721) | ACCEPT(3) Ozancin, Shostack, Wall | MODIFY(2) Baker, Frech | REJECT(1) Northcutt | Northcutt> The definition is? | Baker> Maybe a rewording of this one too. I think most people would agree on | some "minimum" policies like 3-5 bad attempts lockout for an hour or | until the administrator unlocks the account. | Suggested rewrite - | A Windows NT account policy does not enforce reasonable minimum | security-critical settings for lockouts, e.g. lockout duration, | lockout after bad logon attempts, etc. | Ozancin> with reservations | What is appropriate? | Frech> XF:nt-thres-lockout | XF:nt-lock-duration | XF:nt-lock-window | XF:nt-perm-lockout | XF:lockout-disabled | View |
565 | CVE-1999-0583 | Candidate | There is a one-way or two-way trust relationship between Windows NT domains. | Proposed (19990728) | NOOP(2) Baker, Christey | REJECT(2) Northcutt, Shostack | Christey> XF:nt-trusted-domain(1284) | View |
Page 113 of 20943, showing 5 records out of 104715 total, starting on record 561, ending on 565