CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3007  CVE-2001-0186  Candidate  Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20010309)  MODIFY(1) Frech | NOOP(2) Lawler, Ziese  Lawler> Very little info available. | Frech> XF:free-java-directory-traversal(6064)  View
2332  CVE-2000-0756  Candidate  Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(2) Frech, LeBlanc | REVIEWING(2) Christey, Wall  LeBlanc> - if a KB article, bulletin, or patch can be found, then | I"ll ACCEPT | Christey> This is the same as MS:MS01-012 (CVE-2001-0145) | See the Bugtraq post by Joel Moses: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Frech> XF:outlook-vcard-dos(5175) | XF:outlook-vcard-bo(6145) | Because there"s another more recent CAN linked to @stake and | Microsoft"s advisories, we"ll link both of our records to both | candiates until a final decision occurs. If a decision has been made | to promote the CVE-2001 entry, then enter my vote as a REJECT for | CVE-2000-0756. | Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175)  View
1903  CVE-2000-0325  Candidate  The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.  Modified (20020222-01)  ACCEPT(5) Armstrong, Baker, Cole, Prosser, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc | REVIEWING(1) Christey  LeBlanc> - same as CVE-1999-1011 | If I"m misunderstanding something here, please correct me. In fact, it has | the same bulletin as a reference. | Frech> XF:jet-vba-shell | Prosser> This entry is not the same as "now" CVE-1999-1011. That entry is "The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands." This one should be correct. | Christey> BUGTRAQ:19990525 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=bugtraq&m=92765973107637&w=2 | NTBUGTRAQ:19990526 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=ntbugtraq&m=92781907215748&w=2 | Christey> The Microsoft advisory itself describes two separate | vulnerabilities, calling the TEXT I-ISAM problem | (CVE-2000-0323) a variant of the VBA Shell problem (this | CAN). In addition, CVE-2000-0323 does *not* appear in Jet | 4.0, while this one does. Since one problem appears in a | different version than the other, CD:SF-LOC suggests keeping | these candidates SPLIT. | | BID:548 | http://www.securityfocus.com/bid/548 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Need to clarify whether the Bugtraq/NTBugtraq posts are | really describing the same issue (those are BID:286).  View
1978  CVE-2000-0400  Candidate  The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user"s system by encoding it within an email message or news post.  Proposed (20000615)  ACCEPT(4) Frech, Levy, Ozancin, Wall | NOOP(2) Cole, Stracener | REJECT(1) Christey | REVIEWING(1) LeBlanc  LeBlanc> COMMENT - this definately will not work if the user has applied the security | patch. I don"t know whether this repros right now, and have sent a query to | find out. | Christey> Is this now documented in MS:MS00-042? | LeBlanc> the problem isn"t in the Active Movie control. What was | observed was a symptom of another problem that got fixed in | some bulletin or another - I don"t remember. | Christey> According to Scott Culp, this existed because | the patch for the Cache Bypass vulnerability (MS:MS00-046, | CVE-2000-0621) was not applied, so this should be REJECTed | as a duplicate of CVE-2000-0621.  View
547  CVE-1999-0561  Candidate  IIS has the #exec function enabled for Server Side Include (SSI) files.  Proposed (19990728)  NOOP(2) Baker, Northcutt | RECAST(1) Shostack | REJECT(1) LeBlanc  LeBlanc> Does not meet definition of a vulnerability. This function is | just enabled. You can turn it off if you want. if you trust the people | putting up your web pages, this isn"t a problem. If you don"t, this is | just one of many things you need to change.  View

Page 20909 of 20943, showing 5 records out of 104715 total, starting on record 104541, ending on 104545

Actions