CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4736  CVE-2002-0344  Candidate  Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.  Proposed (20020502)  ACCEPT(4) Baker, Cole, Frech, Prosser | NOOP(3) Cox, Foat, Wall  Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2002.02.28a.html  View
3929  CVE-2001-1125  Candidate  Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.  Proposed (20020315)  ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall  Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split  View
3365  CVE-2001-0552  Candidate  ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.  Proposed (20010829)  ACCEPT(6) Armstrong, Baker, Bishop, Cole, Prosser, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Prosser> HP:HPSBUX0106-154 and http://www.cert.org/advisories/CA-2001-24.html | Frech> XF:openview-nnm-ovactiond-execution(6683)  View
156  CVE-1999-0156  Candidate  wu-ftpd FTP daemon allows any user and password combination.  Proposed (19990714)  ACCEPT(2) Northcutt, Shostack | NOOP(1) Baker | RECAST(1) Frech | REVIEWING(2) Christey, Prosser  Prosser> but so far can find no reference to this one | Frech> Our records indicate that this does not necessarly affect just wu-ftp (ie, | also affects IIS FTP server). | Christey> The references for XF:ftp-pwless are not specific enough, | e.g. in terms of version numbers. Perhaps this candidate | should be rejected due to insufficient information.  View
1751  CVE-2000-0173  Candidate  Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service.  Proposed (20000322)  ACCEPT(3) Baker, Blake, Cole | MODIFY(1) Frech | NOOP(4) LeBlanc, Ozancin, Prosser, Wall | REVIEWING(2) Christey, Levy  Prosser> Although SCO is reporting the problem, there is too little info | available to make an informed decision. Unable to find anything | anywhere on this. It is an events logging system, so one would assume | that there is a way to fill up the log and cause a system halt, but no | way of confirming this with limited information. | Christey> Perhaps we should create a content decision, say | CD:VAGUE-ACK, which says whether it"s reasonable to | ACCEPT vendor-acknowledged problems that do not provide any | salient details, as in this candidate as well as several | others. | Cole> I researched this a little more and you can change my NOOP to an | ACCEPT | Frech> XF:sco-eels-dos  View

Page 19 of 20943, showing 5 records out of 104715 total, starting on record 91, ending on 95

Actions