CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
641 | CVE-1999-0659 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). Notes: the former description is: "A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present." | Modified (20080731) | REJECT(3) Baker, Northcutt, Wall | Wall> Don"t consider this a service or a problem. | Baker> concur with wall on this | View |
5018 | CVE-2002-0628 | Candidate | The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute force attack. | Modified (20080808) | ACCEPT(2) Baker, Cole | NOOP(2) Cox, Wall | View | |
2532 | CVE-2000-0963 | Candidate | Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS. | Modified (20080819) | ACCEPT(2) Cole, Mell | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> Various vendor writeups indicate that there are multiple | overflows, so maybe this needs to be SPLIT. | | ADDREF FREEBSD:FreeBSD-SA-00:68 | ADDREF DEBIAN:20001121 ncurses: local privilege escalation | http://www.debian.org/security/2000/20001121 | ADDREF REDHAT:RHSA-2000:115 | http://www.redhat.com/support/errata/RHSA-2000-115.html | BUGTRAQ:20001201 Immunix OS Security update for ncurses | http://marc.theaimsgroup.com/?l=bugtraq&m=97570745306444&w=2 | Frech> XF:libmytinfo-bo(4422) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> This is all a library issue in which TERM/TERMINFO_DIRS are | one possible attack vector, but another is through entries | in the .terminfo file. Add .terminfo and termcap to the | description, as well as libncurses. | | ADDREF MANDRAKE:MDKSA-2001:052 | URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-052.php3 | | Now need to examine whether this is a dupe of CVE-2002-0062, | and/or BID:2116. There"s certainly enough confusion to go | around. | CHANGE> [Christey changed vote from REVIEWING to NOOP] | Christey> This is not a dupe of CVE-2002-0062. As explained in | DEBIAN:DSA-113, the original patches for CVE-2000-0963 | didn"t catch every problem. | | ADDREF SUSE:SuSE-SA:2000:043 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97267560724404&w=2 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
5574 | CVE-2002-1190 | Candidate | Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls. | Modified (20080822) | ACCEPT(4) Baker, Cole, Green, Jones | NOOP(1) Cox | View | |
3560 | CVE-2001-0753 | Candidate | Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges. | Modified (20080822) | ACCEPT(4) Armstrong, Baker, Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:cisco-cbos-gain-information(6453) | View |
Page 20501 of 20943, showing 5 records out of 104715 total, starting on record 102501, ending on 102505