CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
550 | CVE-1999-0565 | Candidate | A Sendmail alias allows input to be piped to a program. | Proposed (19990728) | ACCEPT(1) Northcutt | NOOP(1) Baker | RECAST(1) Shostack | REVIEWING(1) Christey | Shostack> Is this a default alias? Is my .procmailrc an instance of this? | Christey> It is not entirely clear whether the simple fact that an alias | pipes into a program should be considered a vulnerability. It | all depends on the behavior of that particular program. This | is one of a number of configuration-related issues from the | "draft" CVE that came from vulnerability scanners. In | general, when we get to general configuration and "policy," | it becomes more difficult to use the current CVE model to | represent them. So at the very least, this candidate (and | similar ones) should be given close consideration and | discussion before being added to the official CVE list. | | Because this candidate is related to general configuration | issues, and we have not completely determined how to handle | such issues in CVE, this candidate cannot be promoted to an | official CVE entry until such issues are resolved. | View |
549 | CVE-1999-0564 | Candidate | An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn"t require a password) or to become disabled. | Proposed (19990728) | ACCEPT(2) Baker, Shostack | NOOP(1) Northcutt | View | |
548 | CVE-1999-0562 | Candidate | The registry in Windows NT can be accessed remotely by users who are not administrators. | Modified (20061101) | ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | RECAST(1) Northcutt | Northcutt> This isn"t all or nothing, users may be allowed to access part of the | registry. | Frech> XF:nt-winreg-all | XF:nt-winreg-net | View |
547 | CVE-1999-0561 | Candidate | IIS has the #exec function enabled for Server Side Include (SSI) files. | Proposed (19990728) | NOOP(2) Baker, Northcutt | RECAST(1) Shostack | REJECT(1) LeBlanc | LeBlanc> Does not meet definition of a vulnerability. This function is | just enabled. You can turn it off if you want. if you trust the people | putting up your web pages, this isn"t a problem. If you don"t, this is | just one of many things you need to change. | View |
546 | CVE-1999-0560 | Candidate | A system-critical Windows NT file or directory has inappropriate permissions. | Proposed (19990803) | ACCEPT(2) Baker, Wall | RECAST(1) Northcutt | Northcutt> I think we should specify these | View |
Page 20834 of 20943, showing 5 records out of 104715 total, starting on record 104166, ending on 104170