CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1165  CVE-1999-1185  Candidate  Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.  Proposed (20010912)  ACCEPT(4) Cole, Foat, Frech, Stracener | NOOP(1) Wall | REVIEWING(1) Christey  Frech> Possible dupe on CVE-1999-1041. | Christey> Possible dupe with CVE-1999-1041.  View
1441  CVE-1999-1461  Candidate  inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.  Proposed (20010912)  ACCEPT(3) Cole, Foat, Stracener | REJECT(1) Frech  Frech> Possible conflict with CVE-2000-0799.  View
1269  CVE-1999-1289  Candidate  ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.  Proposed (20010912)  ACCEPT(3) Cole, Frech, Wall | NOOP(1) Foat  Frech> Override EX-BETA in this case, since ICQ is always in beta | and is | widely run in production environments.  View
500  CVE-1999-0503  Candidate  A Windows NT local user or administrator account has a guessable password.  Proposed (19990714)  ACCEPT(4) Baker, Meunier, Northcutt, Shostack | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> Note: I am assuming that this entry includes Windows 2000 accounts and | machine/service accounts listed in User Manager. | XF:nt-guess-admin | XF:nt-guess-user | XF:nt-guess-guest | XF:nt-guessed-operpwd | XF:nt-guessed-powerwd | XF:nt-guessed-disabled | XF:nt-guessed-backup | XF:nt-guessed-acctoper-pwd | XF:nt-adminuserpw | XF:nt-guestuserpw | XF:nt-accountuserpw | XF:nt-operator-userpw | XF:nt-service-user-pwd | XF:nt-server-oper-user-pwd | XF:nt-power-user-pwd | XF:nt-backup-operator-userpwd | XF:nt-disabled-account-userpwd | Christey> This candidate is affected by the CD:CF-PASS content decision, | which determines the appropriate level of abstraction to | use for password problems. CD:CF-PASS needs to be accepted | by the Editorial Board before this candidate can be | converted into a CVE entry; the final version of CD:CF-PASS | may require using a different LOA than this candidate is | currently using.  View
505  CVE-1999-0508  Candidate  An account on a router, firewall, or other network device has a default, null, blank, or missing password.  Proposed (19990714)  ACCEPT(4) Baker, Meunier, Northcutt, Shostack | MODIFY(1) Frech | NOOP(1) Christey  Frech> Note: Because the distinction between network hardware and software is not | distinct, | the term "network device" was liberally interpreted. Feel free to reject any | of the | below terms. | XF:default-netranger | XF:cayman-gatorbox | XF:breezecom-default-passwords | XF:default-portmaster | XF:wingate-unpassworded | XF:netopia-unpassworded | XF:default-bay-switches | XF:motorola-cable-default-pass | XF:default-flowpoint | XF:qms-2060-no-root-password | XF:avirt-ras-password | XF:webtrends-rtp-serv-install-password | XF:cisco-bruteforce | XF:cisco-bruteadmin | XF:sambar-server-defaults | XF:management-pfcuser | XF:http-cgi-wwwboard-default | Christey> DELREF XF:avirt-ras-password - does not fit CVE-1999-0508.  View

Page 225 of 20943, showing 5 records out of 104715 total, starting on record 1121, ending on 1125

Actions