CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
865 | CVE-1999-0885 | Candidate | Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL. | Modified (20000313-01) | ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(5) Armstrong, Blake, Christey, Cole, LeBlanc | Christey> This candidate is unconfirmed by the vendor. | Blake> Same as CVE-1999-0776. | Frech> XF:alibaba-url-file-manipulation | Christey> CD:SF-LOC and CD:SF-EXEC may say to merge this candidate with | the problems described in: | BUGTRAQ:20000718 Multiple bugs in Alibaba 2.0 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html | | If so, then ADDREF BID:1485 as well. | Christey> Include the names of the affected CGI"s, including tst.bat, | get32.exe, alibaba.pl, etc. | View |
1725 | CVE-2000-0147 | Candidate | snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host"s configuration. | Modified (20000321-01) | ACCEPT(5) Baker, Bishop, Blake, Cole, Levy | MODIFY(1) Frech | NOOP(1) LeBlanc | Frech> XF:sco-openserver-snmpd | View |
1738 | CVE-2000-0160 | Candidate | The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software"s manufacturer is Microsoft. | Modified (20000321-01) | ACCEPT(4) Baker, LeBlanc, Levy, Wall | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Christey | Christey> In a followup to Bugtraq, Juan Carlos Cuartango makes some | clarifications, specifically that the code that is executed | *must* be signed by Microsoft. | | See BUGTRAQ:20000222 MS signed softwrare privileges | | Microsoft sends some followups, including a statement that it | will include notification. | | The question is, does this belong in CVE? There is no known | means of exploitation; on the other hand, it is related | to privacy concerns. Several posts to the Bugtraq list | indicate that some people believe that unprompted installation | is a significant concern. | Frech> XF:win-active-setup | Levy> BID 999 | | I do consider this vulnerability as it allows a malicious web page | to install *old* and *vulnerable* components signed by microsoft. | LeBlanc> Fixed in MS00-042 | Christey> BID:999 | Also add XF:ie-active-setup-download ? | View |
1732 | CVE-2000-0154 | Candidate | The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack. | Modified (20000403-01) | ACCEPT(1) Cole | NOOP(3) Baker, LeBlanc, Wall | REJECT(3) Christey, Frech, Levy | Christey> DUPE CVE-2000-0224 | Frech> DUPE MITRE:CVE-2000-0224; XF:sco-openserver-arc-symlink | Recommend moving BID reference to CVE-2000-0224. | View |
1736 | CVE-2000-0158 | Candidate | Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon. | Modified (20000403-01) | ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | Frech> XF:sco-mmdf-bo | View |
Page 20378 of 20943, showing 5 records out of 104715 total, starting on record 101886, ending on 101890