CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2138 | CVE-2000-0562 | Candidate | BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower. | Proposed (20000712) | ACCEPT(3) Armstrong, Cole, Levy | MODIFY(2) Baker, Frech | NOOP(1) Ozancin | REVIEWING(1) Christey | Levy> What do others think? Should this be a vuln? I can see the argument | that some features are simply not available unless you use the maximum | security settings. | Christey> At the very least, this needs to be modified to state that | this problem/concern applies to high ports in general, not | just Back orifice. | | The Bugtraq poster claims that BlackICE "shuts down" the port, | but only *after* some initial traffic "leaks" out. This may | be by design, but it does mean that there is a small window | of opportunity in which BlackICE may not work "as | advertised," even at lower security settings. | Christey> XF:blackice-security-level-nervous | BID:1389 | Frech> XF:blackice-security-level-nervous(4777) | CHANGE> [Levy changed vote from REVIEWING to ACCEPT] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Baker> I accept it more as a security exposure, than a real vulnerability. | It performs just as any other "firewall" or IDS product can be configured to | allow traffic without notifying the user. You can adjust settings on | any product that allow traffic that other people or organizations would | find unacceptable. So, as long as it is reflected that this is more of | a configuration that allows such traffic as opposed to a defective | or improperly functioning software issue, I don"t have a problem with | it. | View |
2139 | CVE-2000-0563 | Candidate | The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) Christey, Wall | REVIEWING(1) LeBlanc | Christey> Confirmed by Scott Culp, but this only applies to | outdated/unsupported versions of the JVM. | Frech> XF:macos-java-security-ignored(5052) | Christey> Consult with Microsoft to ensure that this is fixed by | MS:MS00-059. If so, then this might not just be in MacOS. | View |
2140 | CVE-2000-0564 | Candidate | The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter. | Proposed (20000712) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(5) Christey, Cole, LeBlanc, Ozancin, Wall | Christey> ADDREF BID:1463 | URL:http://www.securityfocus.com/bid/1463 | Frech> XF:icq-webfront-guestbook-dos(4574) | View |
2148 | CVE-2000-0572 | Candidate | The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges. | Proposed (20000719) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Cole, LeBlanc, Magdych, Wall | Frech> XF;razor-weak-encryption(4875) | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
2150 | CVE-2000-0574 | Candidate | FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands. | Proposed (20000719) | ACCEPT(3) Cole, Levy, Magdych | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | REVIEWING(1) Christey | Christey> CD:SF-CODEBASE applies here. There are many ftpd"s that | have this setproctitle() problem, but it might be traced | back to the same codebase. See if the HP problem is the | same here as well, and if so, ADDREF HP:HPSBUX0007-117 | URL:http://www.securityfocus.com/templates/advisory.html?id=2404 | Frech> XF:ftp-setproctitle-format-string(4908) | BID:1438 does not exist. | Christey> ADDREF HP:HPSBUX0007-117?? | http://archives.neohapsis.com/archives/hp/2000-q4/0020.html | Christey> ADDREF BID:650 ? | View |
Page 20587 of 20943, showing 5 records out of 104715 total, starting on record 102931, ending on 102935