CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2101  CVE-2000-0524  Candidate  Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.  Proposed (20000712)  MODIFY(3) Frech, LeBlanc, Levy | NOOP(1) Ozancin | RECAST(1) Wall  Levy> There was plenty of people that could not reproduce the problem although | some did. More research (as in actual testing) is probably required. | LeBlanc> This entry does not specify which versions of Outloook are vulnerable, nor | is that clear from the BUGTRAQ record. It is much too broad to say just | "Outlook" when it is definately not all versions of Outlook. The problem | appears confined to some version of Outlook 97, and if I recall correctly, | there has been a patch for this for quite some time. | Frech> XF:outlook-header-dos(4645) | CHANGE> [Wall changed vote from REVIEWING to RECAST] | Wall> UNABLE TO DUPLICATE  View
2103  CVE-2000-0526  Candidate  mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20000712)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> ADDREF XF:mailstudio-view-files | Frech> XF:mailstudio-view-files(4737)  View
2104  CVE-2000-0527  Candidate  userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.  Proposed (20000712)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> Modify description - explicitly mention %0a string; other | metachar"s are filtered | Frech> XF:mailstudio-cgi-input-vaildation(4739)  View
2112  CVE-2000-0535  Candidate  OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.  Proposed (20000712)  ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | REVIEWING(1) Christey  Christey> ADDREF NETBSD | http://archives.neohapsis.com/archives/bugtraq/2000-06/0208.html | | Frech> XF:freebsd-alpha-weak-encryption(4704) | Christey> ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-007.txt.asc | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Should the NetBSD problem really be combined with this?  View
2121  CVE-2000-0544  Candidate  Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.  Proposed (20000712)  ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Ozancin | REVIEWING(2) Christey, Wall  Frech> XF;nt-smb-request-dos(4600) | Christey> Consult with Microsoft to see if this is MS:MS00-066 | Christey> ADDREF MS:MS00-066 | (confirmed offline with David LeBlanc) | Subsequently, add BID:1673 and XF:win2k-rpc-dos(5222)  View

Page 20585 of 20943, showing 5 records out of 104715 total, starting on record 102921, ending on 102925

Actions