CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1993  CVE-2000-0415  Candidate  Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.  Proposed (20000615)  ACCEPT(3) Levy, Ozancin, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cole, Stracener | REJECT(1) LeBlanc  LeBlanc> The poster re-discovered a vulnerability we patched two years | ago, in | http://www.microsoft.com/technet/security/bulletin/ms98-008.asp | Microsoft posted a response to BugTraq when this one went | public, and reminded them that we"d already patched it. | | BTW, I think we want to try and pay attention to follow-ups to | these threads in order to minimize noise in the process. | Christey> Based on David"s comments, this is covered by CVE-1999-0002. | However, that candidate may wind up being SPLIT, so I will | keep this one around for the moment. | | With respect to watching followups, we are relying quite | a bit on other data feeds instead of doing our own reviews | of all the different data sources. The data feeds may report | these problems as new before corrections are posted. | Followups do often lend additional information to the | candidates, and as is the case with this one, we will | often catch the discrepancy before the candidate becomes an | official entry, whether by MITRE"s own analysis or by that | of other Board members. | Frech> XF:outlook-image-long-filename  View
1998  CVE-2000-0420  Candidate  The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.  Proposed (20000615)  ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) Cole, Stracener | REJECT(1) LeBlanc | REVIEWING(1) Wall  LeBlanc> This is not a vulnerability. It is essentially an advisory on best | practices. Also, the description is extremely inaccurate. If I weren"t | intimately familiar with the issue, I would not be able to understand it | from this. Syskey, when applied at lower levels, has well-documented | limitations. | Stracener> "..to recover" | Frech> XF:win2k-syskey-default-configuration | Change "tor ecover" to "to recover"  View
2000  CVE-2000-0422  Candidate  Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.  Proposed (20000615)  ACCEPT(5) Frech, Levy, Ozancin, Prosser, Stracener | NOOP(2) Baker, Cole    View
2001  CVE-2000-0423  Candidate  Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.  Proposed (20000615)  ACCEPT(5) Frech, Levy, Ozancin, Prosser, Stracener | NOOP(2) Baker, Cole    View
2007  CVE-2000-0429  Candidate  A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.  Proposed (20000615)  ACCEPT(3) Ozancin, Prosser, Stracener | MODIFY(2) Frech, Levy | NOOP(2) Baker, Cole  Levy> Reference: BID 1153 | Frech> XF:cart32-admin-password  View

Page 20581 of 20943, showing 5 records out of 104715 total, starting on record 102901, ending on 102905

Actions