CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1215 | CVE-1999-1235 | Candidate | Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user"s index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link. | Proposed (20010912) | ACCEPT(4) Cole, Foat, Frech, Wall | CHANGE> [Foat changed vote from NOOP to ACCEPT] | View |
1214 | CVE-1999-1234 | Candidate | LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo. | Proposed (20010912) | ACCEPT(3) Cole, Frech, Wall | NOOP(1) Foat | View | |
1213 | CVE-1999-1233 | Entry | IIS 4.0 does not properly restrict access for the initial session request from a user"s IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability. | View | |||
1212 | CVE-1999-1232 | Candidate | Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program. | Modified (20060503) | ACCEPT(1) Frech | NOOP(2) Cole, Foat | View | |
1211 | CVE-1999-1231 | Candidate | ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | View |
Page 20701 of 20943, showing 5 records out of 104715 total, starting on record 103501, ending on 103505