CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2332 | CVE-2000-0756 | Candidate | Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(2) Frech, LeBlanc | REVIEWING(2) Christey, Wall | LeBlanc> - if a KB article, bulletin, or patch can be found, then | I"ll ACCEPT | Christey> This is the same as MS:MS01-012 (CVE-2001-0145) | See the Bugtraq post by Joel Moses: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Frech> XF:outlook-vcard-dos(5175) | XF:outlook-vcard-bo(6145) | Because there"s another more recent CAN linked to @stake and | Microsoft"s advisories, we"ll link both of our records to both | candiates until a final decision occurs. If a decision has been made | to promote the CVE-2001 entry, then enter my vote as a REJECT for | CVE-2000-0756. | Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175) | View |
2333 | CVE-2000-0757 | Candidate | The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed. | Proposed (20000921) | ACCEPT(2) Baker, Levy | NOOP(4) Christey, Cole, Wall, Williams | Christey> XF:totalbill-remote-execution | http://xforce.iss.net/static/5068.php | View |
2336 | CVE-2000-0760 | Candidate | The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension. | Proposed (20000921) | ACCEPT(2) Baker, Levy | NOOP(3) Cole, Wall, Williams | View | |
2345 | CVE-2000-0769 | Candidate | O"Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe. | Proposed (20000921) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Christey, Cole | REVIEWING(1) Wall | Christey> XF:website-pro-upload-files(5157) | Frech> XF:website-pro-upload-files(5157) | View |
2350 | CVE-2000-0774 | Candidate | The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root. | Proposed (20000921) | ACCEPT(3) Baker, Levy, Williams | NOOP(2) Cole, Wall | Baker> Vendor fixed this issue in later version of the software | View |
Page 20595 of 20943, showing 5 records out of 104715 total, starting on record 102971, ending on 102975