CVE List

Id CVE No. Status Description Phase Votes Comments Actions
560  CVE-1999-0578  Candidate  A Windows NT system"s registry audit policy does not log an event success or failure for security-critical registry keys.  Proposed (19990721)  ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) Northcutt  Ozancin> with reservation | Again what is defined as critical | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-object-audit(228)  View
1797  CVE-2000-0219  Candidate  Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.  Modified (20141101)  ACCEPT(4) Armstrong, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(4) Baker, Blake, LeBlanc, Wall | REVIEWING(1) Christey  Ozancin> We need an additional CVE entry for other distributions that simply drop you | into a root shell in single user mode. | Christey> Based on Craig"s comments, need to consider if this is an LOA | issue. | Frech> XF:redhat-single-user-auth(4026)  View
559  CVE-1999-0577  Candidate  A Windows NT system"s file audit policy does not log an event success or failure for non-critical files or directories.  Proposed (19990721)  ACCEPT(2) Shostack, Wall | MODIFY(3) Baker, Frech, Ozancin | REJECT(1) Northcutt  Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Perhaps only failure should be logged. | Frech> XF:nt-object-audit | CHANGE> [Baker changed vote from REVIEWING to MODIFY] | Baker> Failure on non-critical files is what should be monitored.  View
2070  CVE-2000-0492  Candidate  PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords.  Proposed (20000712)  ACCEPT(1) Levy | MODIFY(2) Frech, Ozancin | NOOP(2) LeBlanc, Wall  Ozancin> change "attacker who can read the password" to "attacker to decrypt and read | the password" | Frech> XF:passwd-weak-encryption(4596)  View
351  CVE-1999-0352  Candidate  ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.  Proposed (19990721)  ACCEPT(2) Baker, Frech | NOOP(2) Northcutt, Wall | RECAST(1) Ozancin  Ozancin> Can we combine this with CVE-1999-0356 - ControlIT(tm) 4.5 and earlier uses | weak encryption.  View

Page 21 of 20943, showing 5 records out of 104715 total, starting on record 101, ending on 105

Actions