CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4714 | CVE-2002-0322 | Candidate | Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing. | Proposed (20020502) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall | Frech> XF:yahooim-plaintext-password(5943) | View |
1108 | CVE-1999-1128 | Candidate | Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:http-ie-exec(462) | Christey> DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html | ADDREF MISC:http://focus.silversand.net/vulner/allbug/ie3.html | View |
1794 | CVE-2000-0216 | Candidate | Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list. | Proposed (20000322) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REJECT(3) Blake, LeBlanc, Levy | REVIEWING(1) Wall | Blake> This is a configuration issue. Should the fact that NT can be configured | to accept a blank Admin password have a CVE entry? | LeBlanc> This is documented as bad practice - if you have a wide distribution | mailing list, you should only allow certain users to send mail to it. | I don"t think we want to start listing all possible admin errors as | vulnerabilities. | Frech> XF:microsoft-mail-client-dos(4893) | Levy> I agree with all the above comments. Furthermore the delivery status | notification RFC makes it clear that mailing list software should | strip messages from DSN headers. I assume Microsoft"s products are | using the DSN standard and not something else. | View |
1042 | CVE-1999-1062 | Candidate | HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat | Frech> DELREF:XF:laserjet-unpassworded(1876) | ADDREF:XF:hp-printer-flood(1818) | View |
1378 | CVE-1999-1398 | Candidate | Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:irix-xfsdump-symlink(7193) | View |
Page 20298 of 20943, showing 5 records out of 104715 total, starting on record 101486, ending on 101490