CVE List

Id CVE No. Status Description Phase Votes Comments Actions
500  CVE-1999-0503  Candidate  A Windows NT local user or administrator account has a guessable password.  Proposed (19990714)  ACCEPT(4) Baker, Meunier, Northcutt, Shostack | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> Note: I am assuming that this entry includes Windows 2000 accounts and | machine/service accounts listed in User Manager. | XF:nt-guess-admin | XF:nt-guess-user | XF:nt-guess-guest | XF:nt-guessed-operpwd | XF:nt-guessed-powerwd | XF:nt-guessed-disabled | XF:nt-guessed-backup | XF:nt-guessed-acctoper-pwd | XF:nt-adminuserpw | XF:nt-guestuserpw | XF:nt-accountuserpw | XF:nt-operator-userpw | XF:nt-service-user-pwd | XF:nt-server-oper-user-pwd | XF:nt-power-user-pwd | XF:nt-backup-operator-userpwd | XF:nt-disabled-account-userpwd | Christey> This candidate is affected by the CD:CF-PASS content decision, | which determines the appropriate level of abstraction to | use for password problems. CD:CF-PASS needs to be accepted | by the Editorial Board before this candidate can be | converted into a CVE entry; the final version of CD:CF-PASS | may require using a different LOA than this candidate is | currently using.  View
499  CVE-1999-0502  Candidate  A Unix account has a default, null, blank, or missing password.  Proposed (19990714)  ACCEPT(4) Baker, Meunier, Northcutt, Shostack | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:passwd-blank | XF:no-pass | XF:dict | XF:sgi-accounts | XF:linux-caldera-lisa | Christey> This candidate is affected by the CD:CF-PASS content decision, | which determines the appropriate level of abstraction to | use for password problems. CD:CF-PASS needs to be accepted | by the Editorial Board before this candidate can be | converted into a CVE entry; the final version of CD:CF-PASS | may require using a different LOA than this candidate is | currently using.  View
498  CVE-1999-0501  Candidate  A Unix account has a guessable password.  Proposed (19990714)  ACCEPT(3) Baker, Northcutt, Shostack | RECAST(2) Frech, Meunier | REVIEWING(1) Christey  Frech> Guessable falls into the class of CVE-1999-0502, since I can guess a | default, null, etc. password. | Suggest changing to something like "has an existing non-default password | that can be guessed." | I"m also including default passwords in this entry. | In that vein, we show the following references: | XF:user-password | XF:passwd-username | XF:default-unix-sync | XF:default-unix-4dgifts | XF:default-unix-bin | XF:default-unix-daemon | XF:default-unix-lp | XF:default-unix-me | XF:default-unix-nuucp | XF:default-unix-root | XF:default-unix-toor | XF:default-unix-tour | XF:default-unix-tty | XF:default-unix-uucp | Christey> This candidate is affected by the CD:CF-PASS content decision, | which determines the appropriate level of abstraction to | use for password problems. CD:CF-PASS needs to be accepted | by the Editorial Board before this candidate can be | converted into a CVE entry; the final version of CD:CF-PASS | may require using a different LOA than this candidate is | currently using. | CHANGE> [Meunier changed vote from ACCEPT to RECAST] | Meunier> This relates only to account password technology, so this candidate is | independent of the operating system, application, web site or other | application of this technology. The appropriate (natural) level of | abstraction is therefore without specifying that it is for UNIX. | Change the description to "An account has a guessable password other | than default, null, blank." This should satisfy Andre"s objection. | | This Candidate should be merged with any candidate relating to | account password technology where "Unix" in the original description | can be replaced by something else.  View
497  CVE-1999-0499  Candidate  NETBIOS share information may be published through SNMP registry keys in NT.  Proposed (19990721)  ACCEPT(5) Baker, Northcutt, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc  Frech> Change wording to "Windows NT." | XF:snmp-netbios | LeBlanc> Share info can be obtained via SNMP queries, but I question | whether this is a vulnerability. The system can be configured not to do | this, and one may argue that SNMP itself is an insecure configuration. | Furthermore, the share information isn"t published via registry keys - | the description could refer to more than one actual issue. SNMP is meant | to allow people to obtain information about systems. I"m willing to | discuss this with the rest of the board.  View
496  CVE-1999-0498  Candidate  TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.  Modified (19990925-01)  ACCEPT(3) Blake, Hill, Northcutt | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Christey  Frech> XF:linux-tftp | Christey> XF:linux-tftp refers to CVE-1999-0183  View

Page 20844 of 20943, showing 5 records out of 104715 total, starting on record 104216, ending on 104220

Actions