CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1848  CVE-2000-0270  Candidate  The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.  Proposed (20000426)  ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall  Christey> ADDREF XF:emacs-tempfile-creation | Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | Frech> XF:emacs-tempfile-creation | Levy> Change BID reference to BID 1126  View
1849  CVE-2000-0271  Candidate  read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.  Proposed (20000426)  ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall  Christey> Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | ADDREF XF:emacs-password-history | Frech> XF:emacs-password-history | Levy> Change BID reference to BID 1127  View
1853  CVE-2000-0275  Candidate  CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user"s PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.  Proposed (20000426)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:cryptoadmin-weak-encryption  View
1858  CVE-2000-0280  Candidate  Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.  Proposed (20000426)  ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | NOOP(1) Baker  Frech> XF:realserver-ramgen-dos  View
1859  CVE-2000-0281  Candidate  Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.  Proposed (20000426)  NOOP(2) Cole, Wall | REJECT(3) Baker, Frech, Levy  Frech> Does not meet CVE candidate requirements. The problem was remedied on the | server end, and no fault exists at the client. Based on | http://archives.neohapsis.com/archives/bugtraq/2000-03/0299.html: | Approximately one hour after receiving the post from BugTraq, | Napster"s servers were patched to prevent this from occurring. | Users of the Napster Win32 client software are NOT vulnerable. | Baker> Agree with Andre  View

Page 20575 of 20943, showing 5 records out of 104715 total, starting on record 102871, ending on 102875

Actions