CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2225 | CVE-2000-0649 | Candidate | IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. | Proposed (20000803) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(2) Christey, Wall | Christey> ADDREF http://support.microsoft.com/support/kb/articles/Q218/1/80.ASP | | Change description to point out that the internal IP address | exposure is due to the default configuration as opposed to | a bug. | Frech> XF:iis-internal-ip-disclosure(5106) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> There are two variants of the same type of issue here. The | KB article shows that IIS 4.0 reveals the IP address in a | Content-Location MIME header field. The NTBugtraq article | says that the IP address is shown in the WWW-Authenticate | MIME header. Which one has been fixed, or both, and when? | Christey> MSKB:Q218180 identifies a problem in which IIS returns the | info in a Content-Location header, but the authentication | realm problem is not specifically mentioned. Are these the | same problem? | View |
1649 | CVE-2000-0071 | Candidate | IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. | Proposed (20000125) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Baker | REJECT(1) Christey | Frech> XF:iis-ida-idq-paths | Christey> Consider adding: | ADDREF BID:1065 | BUGTRAQ:20000309 Enumerate Root Web Server Directory Vulnerability for IIS 4.0 | Are there really 2 different threads on the same problem? | | Also consider XF:iis-root-enum | | May also be a dupe of CVE-1999-0450 (BID:194) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Appears to be a duplicate of CVE-2000-0098. Confirm with | Microsoft, and if it is a duplicate, then REJECT this | candidate. | CHANGE> [Christey changed vote from REVIEWING to REJECT] | Christey> Confirmed duplicate by Microsoft. | Christey> iis-ida-idq-paths(4346) is obsolete; ensure | http-indexserver-path(3890) is added to CVE-2000-0098. | View |
488 | CVE-1999-0490 | Candidate | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user"s files via an IMG SRC tag. | Modified (19991205-01) | ACCEPT(2) Landfield, Wall | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REVIEWING(1) Christey | Frech> XF:ie-scriplet-fileread | Christey> Duplicate of CVE-1999-0347? | View |
187 | CVE-1999-0187 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | Modified (20050204) | ACCEPT(2) Hill, Northcutt | RECAST(3) Baker, Frech, Prosser | REJECT(1) Dik | REVIEWING(1) Christey | Prosser> The Sun Patches in Ref roll-up fixes for an earlier BO in | rdist lookup( )(ref CERT 96.14)as well as the BO in rdist function expstr() | (ref CERT 97-23) and various vendor bulletins. However both of these rdist | BO"s affect many more OSs than just Sun, i.e., BSD/OS 2.1, DEC OSF"s, AIX, | FreeBSD, SCO, SGI, etc. Believe this falls into the SF-codebase content | decision | Frech> XF:rdist-bo (error msg formation) | XF:rdist-bo2 (execute code) | XF:rdist-bo3 (execute user-created code) | XF:rdist-sept97 (root from local) | Christey> Duplicate of CVE-1999-0022 (SUN:00179 is referenced in | CERT:CA-97.23.rdist), but as Mike and Andre noted, there | are multiple flaws here, so a RECAST may be necessary. | Dik> As currently phrasedm thissa duplicate of CVE-1999-0022 | Baker> Based on our new philosophy, this should be recast/merged or re-described. | View |
204 | CVE-1999-0205 | Candidate | Denial of service in Sendmail 8.6.11 and 8.6.12. | Modified (19990925-01) | ACCEPT(2) Hill, Northcutt | MODIFY(2) Frech, Prosser | NOOP(1) Baker | REVIEWING(2) Christey, Ozancin | Frech> XF:sendmail-alias-dos | Prosser> additional source | Bugtraq | "Re: SM 8.6.12" | http://www.securityfocus.com | Christey> The Bugtraq thread does not provide any proof, including a | comment by Eric Allman that he hadn"t been provided any | details either. | | See http://www.securityfocus.com/templates/archive.pike?list=1&date=1995-07-8&thread=199507131402.KAA02492@bedbugs.net.ohio-state.edu | for the thread. | Christey> Change Bugtraq reference date to 19950708. | View |
Page 20060 of 20943, showing 5 records out of 104715 total, starting on record 100296, ending on 100300