CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4714  CVE-2002-0322  Candidate  Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.  Proposed (20020502)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall  Frech> XF:yahooim-plaintext-password(5943)  View
1108  CVE-1999-1128  Candidate  Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.  Proposed (20010912)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Christey, Foat  Frech> XF:http-ie-exec(462) | Christey> DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html | ADDREF MISC:http://focus.silversand.net/vulner/allbug/ie3.html  View
1794  CVE-2000-0216  Candidate  Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.  Proposed (20000322)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REJECT(3) Blake, LeBlanc, Levy | REVIEWING(1) Wall  Blake> This is a configuration issue. Should the fact that NT can be configured | to accept a blank Admin password have a CVE entry? | LeBlanc> This is documented as bad practice - if you have a wide distribution | mailing list, you should only allow certain users to send mail to it. | I don"t think we want to start listing all possible admin errors as | vulnerabilities. | Frech> XF:microsoft-mail-client-dos(4893) | Levy> I agree with all the above comments. Furthermore the delivery status | notification RFC makes it clear that mailing list software should | strip messages from DSN headers. I assume Microsoft"s products are | using the DSN standard and not something else.  View
1042  CVE-1999-1062  Candidate  HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.  Proposed (20010912)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat  Frech> DELREF:XF:laserjet-unpassworded(1876) | ADDREF:XF:hp-printer-flood(1818)  View
1378  CVE-1999-1398  Candidate  Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.  Proposed (20010912)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:irix-xfsdump-symlink(7193)  View

Page 20298 of 20943, showing 5 records out of 104715 total, starting on record 101486, ending on 101490

Actions