CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2350 | CVE-2000-0774 | Candidate | The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root. | Proposed (20000921) | ACCEPT(3) Baker, Levy, Williams | NOOP(2) Cole, Wall | Baker> Vendor fixed this issue in later version of the software | View |
2349 | CVE-2000-0773 | Entry | Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack. | View | |||
2348 | CVE-2000-0772 | Candidate | The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password. | Modified (20010116-01) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:tumbleweed-mms-blank-password | http://xforce.iss.net/static/5072.php | Frech> XF:umbleweed-mms-blank-password(5072) | View |
2347 | CVE-2000-0771 | Entry | Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability. | View | |||
2346 | CVE-2000-0770 | Entry | IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability. | View |
Page 20474 of 20943, showing 5 records out of 104715 total, starting on record 102366, ending on 102370