CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
970 | CVE-1999-0990 | Candidate | Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system. | Interim (19991229) | ACCEPT(3) Blake, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker | Frech> XF:verbose-auth-identify-user(3804) | View |
1721 | CVE-2000-0143 | Candidate | The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP. | Interim (20001011) | ACCEPT(3) Blake, Cole, LeBlanc | MODIFY(1) Frech | NOOP(2) Baker, Bishop | REJECT(1) Levy | REVIEWING(1) Christey | Frech> XF:ssh-redirect-tcp-connection | CHANGE> [Cole changed vote from REVIEWING to ACCEPT] | Christey> Examine the thread at | http://marc.theaimsgroup.com/?l=bugtraq&m=95055978131077&w=2 | to ensure that this problem is being characterized | appropriately. | Levy> SSH is working as designed. The fact that some of its interactions | are not forseen by some is not a vulnerability. | View |
2388 | CVE-2000-0812 | Candidate | The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag. | Interim (20010117) | ACCEPT(2) Baker, Dik | MODIFY(2) Frech, Levy | NOOP(3) Armstrong, Cole, Wall | REVIEWING(1) Christey | Frech> XF:sunjava-webadmin-bbs(5135) | Levy> BID 1600 | Frech> We also show this associated with CVE-2000-0629: The default | configuration of the Sun Java web server 2.0 and earlier allows remote | attackers to execute arbitrary commands by uploading Java code to the | server via board.html, then directly calling the JSP compiler | servlet. CVE web site concurs. | Christey> I think that Casper Dik confirmed that CVE-2000-0629 is a | configuration problem, and this one is a bug, so they are | different problems. I need to dig up that email, though... | Dik> CVE-2000-0629 indeed is about sample code which shouldn"t | be run on prodution servers | This one is an actual bug and patches have been produced | for JWS 2.0 and 1.1.3 | View |
2665 | CVE-2000-1098 | Candidate | The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request. | Interim (20010117) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall | Frech> The company"s name is SonicWALL. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:sonicwall-empty-request-dos(6042) | The company"s name is SonicWALL. | View |
3254 | CVE-2001-0436 | Candidate | dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program. | Interim (20010911) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:dcforum-az-expr(6392) | View |
Page 20366 of 20943, showing 5 records out of 104715 total, starting on record 101826, ending on 101830