CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1783  CVE-2000-0205  Candidate  Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients.  Proposed (20000322)  ACCEPT(4) Baker, Blake, Cole, Levy | MODIFY(1) Frech | NOOP(3) LeBlanc, Ozancin, Wall  Frech> XF:trendmicro-admin-command(4041)  View
1791  CVE-2000-0213  Candidate  The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.  Proposed (20000322)  ACCEPT(6) Armstrong, Baker, Blake, Cole, Frech, Levy | NOOP(3) LeBlanc, Ozancin, Wall    View
1817  CVE-2000-0239  Candidate  Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.  Proposed (20000412)  ACCEPT(3) Baker, Frech, Levy | NOOP(2) Cole, Magdych  CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
1819  CVE-2000-0241  Candidate  vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges.  Proposed (20000412)  ACCEPT(3) Baker, Frech, Levy | NOOP(2) Cole, Magdych  CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
1820  CVE-2000-0242  Candidate  WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.  Proposed (20000412)  ACCEPT(2) Cole, Levy | NOOP(1) Baker | RECAST(1) Frech | REJECT(2) Christey, Magdych  Frech> Violation of fundamentum divisionis (that is, it"s more than one issue) and | a potential nitpick: | - windmail-fileread: allows remote attackers to read arbitrary files | - windmail-pipe-command: execute commands via shell metacharacters | - The conjunction "or" should be "and", if you decide to stick with one CAN. | Christey> As Andre basically said without naming content decisions, | CD:SF-LOC says this should be split. | | HOWEVER - the author of the product says that WindMail isn"t | supposed to be a CGI script, and says that the pipe | character problem is not related to Geocel. So should CVE | record when someone runs a program that wasn"t intended to | be a CGI? There may be a level of abstraction issue here. | Note that Perl and shell interpreters in CGI-BIN are | already mentioned in CVE-1999-0509. If we want to include | "using a program that wasn"t designed to be a CGI" as a | problem, we should have a separate candidate. | | See the author"s comments at: | http://www.securityfocus.com/templates/archive.pike?list=1&msg=3.0.5.32.20000331114325.013af680@mailhost.geocel.com | | which also claims that the original announcer hasn"t provided | any more details after the author was unable to reproduce the | problem. | CHANGE> [Magdych changed vote from REVIEWING to REJECT] | Magdych> After reviewing the author"s comments, I"m inclined to think that this is more of a misconfiguration than a vulnerability.  View

Page 20573 of 20943, showing 5 records out of 104715 total, starting on record 102861, ending on 102865

Actions