CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1964 | CVE-2000-0386 | Candidate | FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email. | Proposed (20000615) | ACCEPT(5) Baker, Frech, Ozancin, Prosser, Stracener | MODIFY(1) Levy | NOOP(1) Cole | Levy> Reference: BID 1159 | View |
1978 | CVE-2000-0400 | Candidate | The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user"s system by encoding it within an email message or news post. | Proposed (20000615) | ACCEPT(4) Frech, Levy, Ozancin, Wall | NOOP(2) Cole, Stracener | REJECT(1) Christey | REVIEWING(1) LeBlanc | LeBlanc> COMMENT - this definately will not work if the user has applied the security | patch. I don"t know whether this repros right now, and have sent a query to | find out. | Christey> Is this now documented in MS:MS00-042? | LeBlanc> the problem isn"t in the Active Movie control. What was | observed was a symptom of another problem that got fixed in | some bulletin or another - I don"t remember. | Christey> According to Scott Culp, this existed because | the patch for the Cache Bypass vulnerability (MS:MS00-046, | CVE-2000-0621) was not applied, so this should be REJECTed | as a duplicate of CVE-2000-0621. | View |
1979 | CVE-2000-0401 | Candidate | Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string. | Proposed (20000615) | ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:pdgsoft-changepw-bo | XF:pdgsoft-redirect-bo | View |
1990 | CVE-2000-0412 | Candidate | The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file. | Proposed (20000615) | ACCEPT(4) Baker, Levy, Ozancin, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Prosser | Frech> ADDREF XF:knapster-view-files | View |
1991 | CVE-2000-0413 | Candidate | The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path. | Proposed (20000615) | ACCEPT(7) Baker, Cole, Frech, LeBlanc, Levy, Ozancin, Stracener | MODIFY(1) Prosser | NOOP(1) Christey | Prosser> additional source Security BugWare | http://161.53.42.3/~crv/security/bugs/NT/fpse10.html comments on page re: | "MS soon to be released service release OSR 1.2 with needed changes." | I haven"t located anything on MS site yet. Anyone help? | Christey> BID:1433 may also refer to this issue. | Christey> [note to self: review comments by Mark Burnett] | Christey> CHANGEREF XF:iis-shtml-reveal-path XF:frontpage-ext-shtml-path(4439) | LeBlanc> Fixes are up on site now - have been for a while. | View |
Page 20580 of 20943, showing 5 records out of 104715 total, starting on record 102896, ending on 102900