CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2154 | CVE-2000-0578 | Candidate | SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user. | Proposed (20000719) | ACCEPT(4) Baker, Blake, Cole, Levy | MODIFY(1) Frech | NOOP(7) Armstrong, Christey, LeBlanc, Magdych, Oliver, Ozancin, Wall | Frech> XF:sgi-mipspro-modify-files(5007) | CHANGE> [Cole changed vote from NOOP to ACCEPT] | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | Christey> SGI:20030605-01-A | URL:ftp://patches.sgi.com/support/free/security/advisories/20030605-01-A | View |
2156 | CVE-2000-0580 | Candidate | Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization. | Proposed (20000719) | ACCEPT(3) Cole, Frech, Levy | REJECT(2) LeBlanc, Magdych | REVIEWING(1) Wall | LeBlanc> Insufficient data. Most of their claims are not reproducible. You can, | however, DoS the telnet server this way. As far as I know, there is no repro | on any of the other ports. I am not sure of fix status at this time | (7/19/00). Also overlaps with CVE-2000-0581 | CHANGE> [Magdych changed vote from REVIEWING to REJECT] | Magdych> The only independent verification of these claims I have heard is for the Telnet denial of service, which is already defined in CVE candidate CVE-2000-0581. | Frech> Replace win2k-cpu-overload-dos(4824) with win2k-telnetserver-dos(4823) | View |
2165 | CVE-2000-0589 | Candidate | SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration. | Proposed (20000719) | ACCEPT(3) Frech, Levy, Magdych | NOOP(3) Cole, LeBlanc, Wall | CHANGE> [Magdych changed vote from REVIEWING to ACCEPT] | View |
2168 | CVE-2000-0592 | Candidate | Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands. | Proposed (20000719) | ACCEPT(4) Cole, Frech, Levy, Magdych | NOOP(1) LeBlanc | REVIEWING(1) Wall | View | |
2181 | CVE-2000-0605 | Candidate | Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords. | Proposed (20000719) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, Cole, LeBlanc, Magdych | REVIEWING(1) Wall | Christey> ADDREF NTBUGTRAQ:20000718 Security Fix for Blackboard CourseInfo 4.0 | URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0040.html | Frech> XF:blackboard-courseinfo-plaintext(4904) | Christey> Vendor acknowledgement is at: | BUGTRAQ:20000719 Security Fix for Blackboard CourseInfo 4.0 | URL:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000719151904.I17986@securityfocus.com | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
Page 20588 of 20943, showing 5 records out of 104715 total, starting on record 102936, ending on 102940