CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1733 | CVE-2000-0155 | Candidate | Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive. | Proposed (20000223) | ACCEPT(4) Baker, Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:nt-autorun-notdefault | Christey> Consider: | http://support.microsoft.com/support/kb/articles/Q155/2/17.asp | http://support.microsoft.com/support/kb/articles/Q136/2/14.asp | View |
539 | CVE-1999-0549 | Candidate | Windows NT automatically logs in an administrator upon rebooting. | Proposed (19990630) | ACCEPT(1) Hill | MODIFY(3) Blake, Frech, Ozancin | NOOP(1) Wall | REJECT(1) Baker | Wall> Don"t know what this is. Don"t think it is a vulnerability and would | initially reject. This is different than just renaming the | administrator account. | Frech> Would appreciate more information on this one, as in a reference. | Blake> Reference: XF:nt-autologin | Ozancin> Needs more detail | Baker> I tried to find the XF:nt-autologin reference, and got no matching records from their search engine. | No refs, no details, should reject | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-autologon(5) | View |
2121 | CVE-2000-0544 | Candidate | Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length. | Proposed (20000712) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Ozancin | REVIEWING(2) Christey, Wall | Frech> XF;nt-smb-request-dos(4600) | Christey> Consult with Microsoft to see if this is MS:MS00-066 | Christey> ADDREF MS:MS00-066 | (confirmed offline with David LeBlanc) | Subsequently, add BID:1673 and XF:win2k-rpc-dos(5222) | View |
2767 | CVE-2000-1200 | Entry | Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users. | View | |||
1297 | CVE-1999-1317 | Entry | Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the ?? object folder using a different case letter (upper or lower) to point to a different device. | View |
Page 176 of 20943, showing 5 records out of 104715 total, starting on record 876, ending on 880