CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1165 | CVE-1999-1185 | Candidate | Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file. | Proposed (20010912) | ACCEPT(4) Cole, Foat, Frech, Stracener | NOOP(1) Wall | REVIEWING(1) Christey | Frech> Possible dupe on CVE-1999-1041. | Christey> Possible dupe with CVE-1999-1041. | View |
1441 | CVE-1999-1461 | Candidate | inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program. | Proposed (20010912) | ACCEPT(3) Cole, Foat, Stracener | REJECT(1) Frech | Frech> Possible conflict with CVE-2000-0799. | View |
1269 | CVE-1999-1289 | Candidate | ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration. | Proposed (20010912) | ACCEPT(3) Cole, Frech, Wall | NOOP(1) Foat | Frech> Override EX-BETA in this case, since ICQ is always in beta | and is | widely run in production environments. | View |
500 | CVE-1999-0503 | Candidate | A Windows NT local user or administrator account has a guessable password. | Proposed (19990714) | ACCEPT(4) Baker, Meunier, Northcutt, Shostack | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> Note: I am assuming that this entry includes Windows 2000 accounts and | machine/service accounts listed in User Manager. | XF:nt-guess-admin | XF:nt-guess-user | XF:nt-guess-guest | XF:nt-guessed-operpwd | XF:nt-guessed-powerwd | XF:nt-guessed-disabled | XF:nt-guessed-backup | XF:nt-guessed-acctoper-pwd | XF:nt-adminuserpw | XF:nt-guestuserpw | XF:nt-accountuserpw | XF:nt-operator-userpw | XF:nt-service-user-pwd | XF:nt-server-oper-user-pwd | XF:nt-power-user-pwd | XF:nt-backup-operator-userpwd | XF:nt-disabled-account-userpwd | Christey> This candidate is affected by the CD:CF-PASS content decision, | which determines the appropriate level of abstraction to | use for password problems. CD:CF-PASS needs to be accepted | by the Editorial Board before this candidate can be | converted into a CVE entry; the final version of CD:CF-PASS | may require using a different LOA than this candidate is | currently using. | View |
505 | CVE-1999-0508 | Candidate | An account on a router, firewall, or other network device has a default, null, blank, or missing password. | Proposed (19990714) | ACCEPT(4) Baker, Meunier, Northcutt, Shostack | MODIFY(1) Frech | NOOP(1) Christey | Frech> Note: Because the distinction between network hardware and software is not | distinct, | the term "network device" was liberally interpreted. Feel free to reject any | of the | below terms. | XF:default-netranger | XF:cayman-gatorbox | XF:breezecom-default-passwords | XF:default-portmaster | XF:wingate-unpassworded | XF:netopia-unpassworded | XF:default-bay-switches | XF:motorola-cable-default-pass | XF:default-flowpoint | XF:qms-2060-no-root-password | XF:avirt-ras-password | XF:webtrends-rtp-serv-install-password | XF:cisco-bruteforce | XF:cisco-bruteadmin | XF:sambar-server-defaults | XF:management-pfcuser | XF:http-cgi-wwwboard-default | Christey> DELREF XF:avirt-ras-password - does not fit CVE-1999-0508. | View |
Page 225 of 20943, showing 5 records out of 104715 total, starting on record 1121, ending on 1125