CVE List

Id CVE No. Status Description Phase Votes Comments Actions
986  CVE-1999-1006  Candidate  Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.  Proposed (19991222)  ACCEPT(4) Baker, Cole, Prosser, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> XF:groupwise-web-path | Prosser> Pretty well confirmed by testing with responses to BugTraq list. | | additional ref: BugTraq ID 879 http://www.securityfocus.com/bid/879 | Christey> A later discovery almost 2 years later is at: | BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell | GroupWise Web Access Path Disclosure Vulnerability | http://marc.theaimsgroup.com/?l=bugtraq&m=101494830315071&w=2 | CD:SF-LOC might suggest merging these together.  View
989  CVE-1999-1009  Candidate  The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user"s system.  Proposed (19991222)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Balinsky, Cole, Stracener, Wall  Frech> XF:disney-search-info(3955) | Balinsky> The go.express.com web site does not mention the existence of the Express web server mentioned in the advisory. There appears to be no way of verifying this.  View
1586  CVE-2000-0008  Candidate  FTPPro allows local users to read sensitive information, which is stored in plain text.  Proposed (20000111)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy  Frech> XF:ftppro-plaintext-information | Christey> ADDREF BID:1790 | ADDREF URL:http://www.securityfocus.com/bid/1790  View
1594  CVE-2000-0016  Candidate  Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username.  Proposed (20000111)  ACCEPT(4) Armstrong, Baker, Levy, Stracener | MODIFY(1) Frech  Frech> XF:iams-pop3-command-dos  View
1595  CVE-2000-0017  Candidate  Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.  Proposed (20000111)  NOOP(4) Armstrong, Baker, Christey, Stracener | REJECT(2) Frech, Levy  Christey> It"s not certain whether this is exploitable or not. An | expert (the linuxconf author?) wasn"t able to duplicate the | bug - see http://lwn.net/1999/1223/a/linuxconfresponse.html | | The original posting with example exploit was | http://marc.theaimsgroup.com/?l=bugtraq&m=94580196627059&w=2 | | However - GIAC and the Security Focus incidents list have | consistently reported that scans are taking place for | linuxconf, so do the hackers know more than we do? | Frech> Unless vendor or other confirmation occurs, there has been no corroboration | of this issue in public forums. | CHANGE> [Armstrong changed vote from ACCEPT to NOOP]  View

Page 20559 of 20943, showing 5 records out of 104715 total, starting on record 102791, ending on 102795

Actions