CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1964  CVE-2000-0386  Candidate  FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.  Proposed (20000615)  ACCEPT(5) Baker, Frech, Ozancin, Prosser, Stracener | MODIFY(1) Levy | NOOP(1) Cole  Levy> Reference: BID 1159  View
1978  CVE-2000-0400  Candidate  The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user"s system by encoding it within an email message or news post.  Proposed (20000615)  ACCEPT(4) Frech, Levy, Ozancin, Wall | NOOP(2) Cole, Stracener | REJECT(1) Christey | REVIEWING(1) LeBlanc  LeBlanc> COMMENT - this definately will not work if the user has applied the security | patch. I don"t know whether this repros right now, and have sent a query to | find out. | Christey> Is this now documented in MS:MS00-042? | LeBlanc> the problem isn"t in the Active Movie control. What was | observed was a symptom of another problem that got fixed in | some bulletin or another - I don"t remember. | Christey> According to Scott Culp, this existed because | the patch for the Cache Bypass vulnerability (MS:MS00-046, | CVE-2000-0621) was not applied, so this should be REJECTed | as a duplicate of CVE-2000-0621.  View
1979  CVE-2000-0401  Candidate  Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.  Proposed (20000615)  ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:pdgsoft-changepw-bo | XF:pdgsoft-redirect-bo  View
1990  CVE-2000-0412  Candidate  The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.  Proposed (20000615)  ACCEPT(4) Baker, Levy, Ozancin, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Prosser  Frech> ADDREF XF:knapster-view-files  View
1991  CVE-2000-0413  Candidate  The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.  Proposed (20000615)  ACCEPT(7) Baker, Cole, Frech, LeBlanc, Levy, Ozancin, Stracener | MODIFY(1) Prosser | NOOP(1) Christey  Prosser> additional source Security BugWare | http://161.53.42.3/~crv/security/bugs/NT/fpse10.html comments on page re: | "MS soon to be released service release OSR 1.2 with needed changes." | I haven"t located anything on MS site yet. Anyone help? | Christey> BID:1433 may also refer to this issue. | Christey> [note to self: review comments by Mark Burnett] | Christey> CHANGEREF XF:iis-shtml-reveal-path XF:frontpage-ext-shtml-path(4439) | LeBlanc> Fixes are up on site now - have been for a while.  View

Page 20580 of 20943, showing 5 records out of 104715 total, starting on record 102896, ending on 102900

Actions