CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1733  CVE-2000-0155  Candidate  Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.  Proposed (20000223)  ACCEPT(4) Baker, Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:nt-autorun-notdefault | Christey> Consider: | http://support.microsoft.com/support/kb/articles/Q155/2/17.asp | http://support.microsoft.com/support/kb/articles/Q136/2/14.asp  View
539  CVE-1999-0549  Candidate  Windows NT automatically logs in an administrator upon rebooting.  Proposed (19990630)  ACCEPT(1) Hill | MODIFY(3) Blake, Frech, Ozancin | NOOP(1) Wall | REJECT(1) Baker  Wall> Don"t know what this is. Don"t think it is a vulnerability and would | initially reject. This is different than just renaming the | administrator account. | Frech> Would appreciate more information on this one, as in a reference. | Blake> Reference: XF:nt-autologin | Ozancin> Needs more detail | Baker> I tried to find the XF:nt-autologin reference, and got no matching records from their search engine. | No refs, no details, should reject | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-autologon(5)  View
2121  CVE-2000-0544  Candidate  Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.  Proposed (20000712)  ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Ozancin | REVIEWING(2) Christey, Wall  Frech> XF;nt-smb-request-dos(4600) | Christey> Consult with Microsoft to see if this is MS:MS00-066 | Christey> ADDREF MS:MS00-066 | (confirmed offline with David LeBlanc) | Subsequently, add BID:1673 and XF:win2k-rpc-dos(5222)  View
2767  CVE-2000-1200  Entry  Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.        View
1297  CVE-1999-1317  Entry  Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the ?? object folder using a different case letter (upper or lower) to point to a different device.        View

Page 176 of 20943, showing 5 records out of 104715 total, starting on record 876, ending on 880

Actions