CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
560 | CVE-1999-0578 | Candidate | A Windows NT system"s registry audit policy does not log an event success or failure for security-critical registry keys. | Proposed (19990721) | ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) Northcutt | Ozancin> with reservation | Again what is defined as critical | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-object-audit(228) | View |
1797 | CVE-2000-0219 | Candidate | Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt. | Modified (20141101) | ACCEPT(4) Armstrong, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(4) Baker, Blake, LeBlanc, Wall | REVIEWING(1) Christey | Ozancin> We need an additional CVE entry for other distributions that simply drop you | into a root shell in single user mode. | Christey> Based on Craig"s comments, need to consider if this is an LOA | issue. | Frech> XF:redhat-single-user-auth(4026) | View |
559 | CVE-1999-0577 | Candidate | A Windows NT system"s file audit policy does not log an event success or failure for non-critical files or directories. | Proposed (19990721) | ACCEPT(2) Shostack, Wall | MODIFY(3) Baker, Frech, Ozancin | REJECT(1) Northcutt | Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Perhaps only failure should be logged. | Frech> XF:nt-object-audit | CHANGE> [Baker changed vote from REVIEWING to MODIFY] | Baker> Failure on non-critical files is what should be monitored. | View |
2070 | CVE-2000-0492 | Candidate | PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(2) Frech, Ozancin | NOOP(2) LeBlanc, Wall | Ozancin> change "attacker who can read the password" to "attacker to decrypt and read | the password" | Frech> XF:passwd-weak-encryption(4596) | View |
351 | CVE-1999-0352 | Candidate | ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption. | Proposed (19990721) | ACCEPT(2) Baker, Frech | NOOP(2) Northcutt, Wall | RECAST(1) Ozancin | Ozancin> Can we combine this with CVE-1999-0356 - ControlIT(tm) 4.5 and earlier uses | weak encryption. | View |
Page 21 of 20943, showing 5 records out of 104715 total, starting on record 101, ending on 105