CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1636  CVE-2000-0058  Candidate  Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.  Proposed (20000125)  MODIFY(2) Baker, Frech | NOOP(1) Christey  Frech> XF:handspring-visor-auth(3873) | Consider removing the security-express.com reference, since it is identical | to the BugTraq reference. The BugTraq reference is (hopefully) not going to | disappear soon, and the security-express.com reference provides no new or | additional information. | Christey> URLs will begin to be included with candidates to support | Board members" voting activities. They will be converted to | the generalized reference format when if candidate is | ACCEPTed and becomes an official entry. | Christey> The problem may not be a lack of authentication (as mentioned | by the poster), but rather weak authentication (the apparent | need to provide the same username). | Baker> MOdify description to indicate the weak authentication  View
1637  CVE-2000-0059  Candidate  PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.  Proposed (20000125)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:php3-popen-execute(3900) | Christey> CONFIRM:http://www.php.net/ChangeLog.php3 | Section dated January 11, 2000 says: "Fix safe-mode problem in | popen() (Kristian)"  View
1639  CVE-2000-0061  Candidate  Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.  Proposed (20000125)  MODIFY(2) Frech, LeBlanc | NOOP(1) Baker | REJECT(1) Christey  Frech> XF:ie-cross-frame-docs(3901) | LeBlanc> - I"d like to see a KB or bulletin referenced | Christey> This is a duplicate of CVE-2000-0156. The FAQ at | http://www.microsoft.com/technet/security/bulletin/fq00-009.asp. | says "the vulnerability requires Active Scripting" and | "it is possible, under very specific conditions, to violate IE"s | cross-domain security model." Also says "the redirect is made, via | the <IMG SRC> HTML tag" | | Need to copy these references over to CVE-2000-0156.  View
1644  CVE-2000-0066  Candidate  WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.  Proposed (20000125)  ACCEPT(2) Baker, Williams | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:website-pro-dir-path | Christey> ADDREF BUGTRAQ:20000113 Re: WebSitePro/2.3.18 + 2.4.9 is revealing Webdirectories | URL:http://www.securityfocus.com/archive/1/41798 | Also BID:932  View
1645  CVE-2000-0067  Candidate  CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.  Proposed (20000125)  ACCEPT(2) Baker, Williams | MODIFY(1) Frech  Frech> XF:cybercash-mck-tmp(3823)  View

Page 20561 of 20943, showing 5 records out of 104715 total, starting on record 102801, ending on 102805

Actions