CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1632  CVE-2000-0054  Candidate  search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.  Proposed (20000125)  MODIFY(1) Frech  Frech> XF:http-cgi-homefree-search  View
1646  CVE-2000-0068  Candidate  daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail.  Proposed (20000125)  MODIFY(1) Frech  Frech> XF:intel-email-unauthenticate-users  View
1647  CVE-2000-0069  Candidate  The recover program in Solstice Backup allows local users to restore sensitive files.  Proposed (20000125)  MODIFY(1) Frech  Frech> XF:solstice-backup-restore-files(3904)  View
5218  CVE-2002-0828  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2002-0862. Reason: This is a duplicate of CVE-2002-0862. Notes: All CVE users should reference CVE-2002-0862 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Modified (20050204)  MODIFY(1) Foat | NOOP(3) Armstrong, Cole, Cox | REJECT(3) Baker, Christey, Frech | REVIEWING(1) Wall  Cox> Why isn"t this sharing the same CVE name as CVE-2002-0970? | Christey> BID:5410 | URL:http://www.securityfocus.com/bid/5410 | CHANGE> [Christey changed vote from NOOP to REJECT] | Christey> This is an original report of a larger issue as described in | CVE-2002-0862. This candidate will be REJECTED and | CVE-2002-0862 will be used in its place, since CVE-2002-0862 | comes from a more authoritative source, and is more accurate. | Foat> This vulneraiblity is valid. It was discovered that the scope is much | greater than indicated in the description, since certificate checking is an OS | function in the Windows environment. A complete listing of the vulnerable | platforms is available at | http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bull | etin/ms02-050.asp. | Frech> Remains associated with XF:ssl-ca-certificate-spoofing(9776)  View
252  CVE-1999-0253  Candidate  IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.  Modified (20000106-01)  ACCEPT(9) Armstrong, Baker, Bishop, Blake, Cole, Collins, Frech, Landfield, Northcutt | MODIFY(1) LeBlanc | NOOP(3) Ozancin, Prosser, Wall | REVIEWING(1) Christey  Christey> This is a problem that was introduced after patching a | previous dot bug with the iis-fix hotfix (see CVE-1999-0154). | Since the hotfix introduced the problem, this should be | treated as a seaprate issue. | Wall> Agree with the comment. | LeBlanc> - this one is so old, I don"t remember it at all and can"t verify or | deny the issue. If you can find some documentation that says we fixed it (KB | article, hotfix, something), then I would change this to ACCEPT | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1814 | URL:http://www.securityfocus.com/bid/1814  View

Page 19849 of 20943, showing 5 records out of 104715 total, starting on record 99241, ending on 99245

Actions