CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1783 | CVE-2000-0205 | Candidate | Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients. | Proposed (20000322) | ACCEPT(4) Baker, Blake, Cole, Levy | MODIFY(1) Frech | NOOP(3) LeBlanc, Ozancin, Wall | Frech> XF:trendmicro-admin-command(4041) | View |
1791 | CVE-2000-0213 | Candidate | The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters. | Proposed (20000322) | ACCEPT(6) Armstrong, Baker, Blake, Cole, Frech, Levy | NOOP(3) LeBlanc, Ozancin, Wall | View | |
1817 | CVE-2000-0239 | Candidate | Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request. | Proposed (20000412) | ACCEPT(3) Baker, Frech, Levy | NOOP(2) Cole, Magdych | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
1819 | CVE-2000-0241 | Candidate | vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges. | Proposed (20000412) | ACCEPT(3) Baker, Frech, Levy | NOOP(2) Cole, Magdych | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
1820 | CVE-2000-0242 | Candidate | WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters. | Proposed (20000412) | ACCEPT(2) Cole, Levy | NOOP(1) Baker | RECAST(1) Frech | REJECT(2) Christey, Magdych | Frech> Violation of fundamentum divisionis (that is, it"s more than one issue) and | a potential nitpick: | - windmail-fileread: allows remote attackers to read arbitrary files | - windmail-pipe-command: execute commands via shell metacharacters | - The conjunction "or" should be "and", if you decide to stick with one CAN. | Christey> As Andre basically said without naming content decisions, | CD:SF-LOC says this should be split. | | HOWEVER - the author of the product says that WindMail isn"t | supposed to be a CGI script, and says that the pipe | character problem is not related to Geocel. So should CVE | record when someone runs a program that wasn"t intended to | be a CGI? There may be a level of abstraction issue here. | Note that Perl and shell interpreters in CGI-BIN are | already mentioned in CVE-1999-0509. If we want to include | "using a program that wasn"t designed to be a CGI" as a | problem, we should have a separate candidate. | | See the author"s comments at: | http://www.securityfocus.com/templates/archive.pike?list=1&msg=3.0.5.32.20000331114325.013af680@mailhost.geocel.com | | which also claims that the original announcer hasn"t provided | any more details after the author was unable to reproduce the | problem. | CHANGE> [Magdych changed vote from REVIEWING to REJECT] | Magdych> After reviewing the author"s comments, I"m inclined to think that this is more of a misconfiguration than a vulnerability. | View |
Page 20573 of 20943, showing 5 records out of 104715 total, starting on record 102861, ending on 102865