CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1991  CVE-2000-0413  Candidate  The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.  Proposed (20000615)  ACCEPT(7) Baker, Cole, Frech, LeBlanc, Levy, Ozancin, Stracener | MODIFY(1) Prosser | NOOP(1) Christey  Prosser> additional source Security BugWare | http://161.53.42.3/~crv/security/bugs/NT/fpse10.html comments on page re: | "MS soon to be released service release OSR 1.2 with needed changes." | I haven"t located anything on MS site yet. Anyone help? | Christey> BID:1433 may also refer to this issue. | Christey> [note to self: review comments by Mark Burnett] | Christey> CHANGEREF XF:iis-shtml-reveal-path XF:frontpage-ext-shtml-path(4439) | LeBlanc> Fixes are up on site now - have been for a while.  View
332  CVE-1999-0333  Candidate  HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.  Modified (19990925-01)  ACCEPT(2) Baker, Frech | MODIFY(1) Prosser | RECAST(1) Christey  Prosser> additional source | HP Security Bulletin 85 | http://us-support.external.hp.com | http://europe-support.external.hp.com | Christey> Two separate bugs, so SF-LOC says this candidate should be | split | Christey> ADDREF CIAC:J-007 | URL:http://ciac.llnl.gov/ciac/bulletins/j-007.shtml  View
237  CVE-1999-0238  Candidate  php.cgi allows attackers to read any file on the system.  Proposed (19990623)  ACCEPT(5) Baker, Collins, Frech, Northcutt, Prosser | NOOP(1) Christey  Prosser> additional source | AUSCERT External Security Bulletin ESB-97.047 | http://www.auscert.org.au | Christey> ADDREF BUGTRAQ:19970416 Update on PHP/FI hole | URL:http://www.dataguard.no/bugtraq/1997_2/0069.html | The attacker specifies the filename as an argument to the | program. | Add "PHP/FI" to description to facilitate search. | AUSCERT URL is ftp://ftp.auscert.org.au/pub/auscert/ESB/ESB-97.047 | Christey> Consider adding BID:2250  View
3454  CVE-2001-0645  Candidate  Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.  Modified (20050510)  ACCEPT(5) Baker, Cole, Frech, Prosser, Ziese | NOOP(2) Foat, Wall  Prosser> Additional Reference | http://www.sarc.com/avcenter/security/Content/2001_05_08.html | Prosser> Add Symantec vendor advisory source | http://securityresponse.symantec.com/avcenter/security/Content/2001_05_08.html  View
2011  CVE-2000-0433  Candidate  The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles.  Proposed (20000615)  ACCEPT(6) Baker, Cole, Frech, Levy, Ozancin, Stracener | MODIFY(1) Prosser  Prosser> add source: | SecurityFocus | BID1357 | SuSE Linux aaabase User Account with /tmp Home Vulnerability | http://www.securityfocus.com/bid/1357 | CHANGE> [Levy changed vote from REVIEWING to ACCEPT]  View

Page 20 of 20943, showing 5 records out of 104715 total, starting on record 96, ending on 100

Actions