CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2332  CVE-2000-0756  Candidate  Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(2) Frech, LeBlanc | REVIEWING(2) Christey, Wall  LeBlanc> - if a KB article, bulletin, or patch can be found, then | I"ll ACCEPT | Christey> This is the same as MS:MS01-012 (CVE-2001-0145) | See the Bugtraq post by Joel Moses: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Frech> XF:outlook-vcard-dos(5175) | XF:outlook-vcard-bo(6145) | Because there"s another more recent CAN linked to @stake and | Microsoft"s advisories, we"ll link both of our records to both | candiates until a final decision occurs. If a decision has been made | to promote the CVE-2001 entry, then enter my vote as a REJECT for | CVE-2000-0756. | Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175)  View
2333  CVE-2000-0757  Candidate  The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.  Proposed (20000921)  ACCEPT(2) Baker, Levy | NOOP(4) Christey, Cole, Wall, Williams  Christey> XF:totalbill-remote-execution | http://xforce.iss.net/static/5068.php  View
2336  CVE-2000-0760  Candidate  The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.  Proposed (20000921)  ACCEPT(2) Baker, Levy | NOOP(3) Cole, Wall, Williams    View
2345  CVE-2000-0769  Candidate  O"Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.  Proposed (20000921)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Christey, Cole | REVIEWING(1) Wall  Christey> XF:website-pro-upload-files(5157) | Frech> XF:website-pro-upload-files(5157)  View
2350  CVE-2000-0774  Candidate  The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.  Proposed (20000921)  ACCEPT(3) Baker, Levy, Williams | NOOP(2) Cole, Wall  Baker> Vendor fixed this issue in later version of the software  View

Page 20595 of 20943, showing 5 records out of 104715 total, starting on record 102971, ending on 102975

Actions