CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2136  CVE-2000-0559  Candidate  eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.  Proposed (20000712)  ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall  Frech> XF:etrust-weak-password-encryption(5051)  View
1998  CVE-2000-0420  Candidate  The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.  Proposed (20000615)  ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) Cole, Stracener | REJECT(1) LeBlanc | REVIEWING(1) Wall  LeBlanc> This is not a vulnerability. It is essentially an advisory on best | practices. Also, the description is extremely inaccurate. If I weren"t | intimately familiar with the issue, I would not be able to understand it | from this. Syskey, when applied at lower levels, has well-documented | limitations. | Stracener> "..to recover" | Frech> XF:win2k-syskey-default-configuration | Change "tor ecover" to "to recover"  View
2139  CVE-2000-0563  Candidate  The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.  Proposed (20000712)  ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) Christey, Wall | REVIEWING(1) LeBlanc  Christey> Confirmed by Scott Culp, but this only applies to | outdated/unsupported versions of the JVM. | Frech> XF:macos-java-security-ignored(5052) | Christey> Consult with Microsoft to ensure that this is fixed by | MS:MS00-059. If so, then this might not just be in MacOS.  View
1822  CVE-2000-0244  Candidate  The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.  Proposed (20000412)  ACCEPT(2) Levy, Magdych | MODIFY(1) Frech | NOOP(2) Baker, Cole  Frech> XF:citrix-encryption  View
2121  CVE-2000-0544  Candidate  Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.  Proposed (20000712)  ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Ozancin | REVIEWING(2) Christey, Wall  Frech> XF;nt-smb-request-dos(4600) | Christey> Consult with Microsoft to see if this is MS:MS00-066 | Christey> ADDREF MS:MS00-066 | (confirmed offline with David LeBlanc) | Subsequently, add BID:1673 and XF:win2k-rpc-dos(5222)  View

Page 20059 of 20943, showing 5 records out of 104715 total, starting on record 100291, ending on 100295

Actions