CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1029  CVE-1999-1049  Candidate  ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:arcserve-agent-passwords(1822)  View
1285  CVE-1999-1305  Candidate  Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access.  Proposed (20010912)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech  Frech> XF:sco-at(7589)  View
1541  CVE-1999-1561  Candidate  Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.  Proposed (20010912)  NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech  Frech> (ACCEPT; Task 2359)  View
1030  CVE-1999-1050  Candidate  Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Christey> Abstraction and definition issue: CD:SF-LOC suggests combining | issues of the same type. Some people refer to "directory | traversal" and just mean .. problems; but there are other | issues (specifying an absolute pathname, using C: drive | letters, doing encodings) that, to my way of thinking, are | "different." Perhaps this should be split. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are.  View
1286  CVE-1999-1306  Candidate  Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.  Proposed (20010912)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> XF:cisco-acl-established(1248) | Possibly duplicate with CVE-1999-0162? | Christey> Might be a duplicate of CVE-1999-0162, but CVE-1999-0162 was | released in 1995, whereas this bug was released in 1992.  View

Page 203 of 20943, showing 5 records out of 104715 total, starting on record 1011, ending on 1015

Actions