CVE List

Id CVE No. Status Description Phase Votes Comments Actions
554  CVE-1999-0570  Candidate  Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.  Proposed (19990728)  ACCEPT(1) Northcutt | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Wall  Northcutt> Here we are crossing into the best practices arena again. However since | passfilt does establish a measurable standard and since we aren"t the | ones defining the stanard, simply saying it should be employed I will | vote for this. | Frech> XF:nt-passfilt-not-inst(1308) | XF:nt-passfilt-not-found(1309) | Christey> Consider MSKB:Q161990 and MSKB:Q151082  View
553  CVE-1999-0569  Candidate  A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.  Modified (19991130-01)  ACCEPT(1) Wall | NOOP(2) Baker, Christey | REJECT(1) Northcutt  Northcutt> I do this intentionally somethings in high content directories | Christey> XF:http-noindex(90) ?  View
556  CVE-1999-0572  Candidate  .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.  Modified (20041017)  ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | NOOP(2) Christey, Northcutt  Northcutt> I don"t quite get what this means, sorry | Frech> XF:nt-regfile(178) | Christey> MISC:http://security-archive.merton.ox.ac.uk/nt-security-199902/0087.html  View
526  CVE-1999-0529  Candidate  A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.  Proposed (19990726)  ACCEPT(1) Frech | MODIFY(2) Baker, Meunier | REJECT(1) Northcutt  Northcutt> I have seen ISPs "assign" private addresses within their domain | Meunier> A border router or firewall forwards packets that claim to come from IANA | reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, | etc, outside of their area of validity. | CHANGE> [Frech changed vote from REVIEWING to ACCEPT] | Baker> I think the description should be modified to say they accept this type of traffic from an interface not residing on private/reserved network.  View
562  CVE-1999-0580  Candidate  The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.  Proposed (19990803)  ACCEPT(1) Wall | NOOP(1) Baker | RECAST(1) Northcutt  Northcutt> I think we can define appropriate, take a look at the nt security .pdf | and see if you can"t see a way to phrase specific keys in a way that | defines inappropriate. | Baker> This is way vague...  View

Page 20917 of 20943, showing 5 records out of 104715 total, starting on record 104581, ending on 104585

Actions