CVE List

Id CVE No. Status Description Phase Votes Comments Actions
186  CVE-1999-0186  Candidate  In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.  Modified (20071119)  ACCEPT(2) Baker, Dik | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> Change XF:snmp-backdoor-access to XF:sol-hidden-commstr | Add ISS:Hidden Community String in SNMP Implementation | Christey> What is the proper level of abstraction to use here? Should | we have a separate entry for each different default community | string? See: | http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and | http://cve.mitre.org/Board_Sponsors/archives/msg00250.html | http://cve.mitre.org/Board_Sponsors/archives/msg00251.html | | Until the associated content decisions have been approved | by the Editorial Board, this candidate cannot be accepted | for inclusion in CVE. | Christey> ADDREF BID:177 | Christey> ISS:19981102 Hidden community string in SNMP implementation | http://xforce.iss.net/alerts/advise11.php | | Change description to include "hidden" | Christey> XF:snmp-backdoor-access is missing.  View
497  CVE-1999-0499  Candidate  NETBIOS share information may be published through SNMP registry keys in NT.  Proposed (19990721)  ACCEPT(5) Baker, Northcutt, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc  Frech> Change wording to "Windows NT." | XF:snmp-netbios | LeBlanc> Share info can be obtained via SNMP queries, but I question | whether this is a vulnerability. The system can be configured not to do | this, and one may argue that SNMP itself is an insecure configuration. | Furthermore, the share information isn"t published via registry keys - | the description could refer to more than one actual issue. SNMP is meant | to allow people to obtain information about systems. I"m willing to | discuss this with the rest of the board.  View
426  CVE-1999-0427  Candidate  Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.  Proposed (19990728)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey  Frech> Change version number to 4.2beta. Second to last paragraph in bugtraq | reference states: "Both the Win 95 and Win NT versions, along with the 4.2 | beta of Eudora are affected." | Christey> This issue seems to have been rediscovered in | BUGTRAQ:20000515 Eudora Pro & Outlook Overflow - too long filenames again | http://marc.theaimsgroup.com/?l=bugtraq&m=95842482413076&w=2 | | Also see | BUGTRAQ:19990320 Eudora Attachment Buffer Overflow | http://marc.theaimsgroup.com/?l=bugtraq&m=92195396912110&w=2 | | Is this a duplicate/subsumed by CVE-1999-0004?  View
515  CVE-1999-0518  Candidate  A NETBIOS/SMB share password is guessable.  Proposed (19990714)  ACCEPT(5) Baker, LeBlanc, Meunier, Northcutt, Shostack | MODIFY(1) Frech  Frech> Change description term to NetBIOS. | XF:nt-netbios-perm | XF:sharepass | XF:win95-smb-password | XF:nt-netbios-dict  View
516  CVE-1999-0519  Candidate  A NETBIOS/SMB share password is the default, null, or missing.  Proposed (19990714)  ACCEPT(5) Baker, LeBlanc, Meunier, Northcutt, Shostack | MODIFY(1) Frech  Frech> Change description term to NetBIOS. | XF:decod-smb-password-empty | XF:nt-netbios-everyoneaccess | XF:nt-netbios-guestaccess | XF:nt-netbios-allaccess | XF:nt-netbios-open | XF:nt-netbios-write | XF:nt-netbios-shareguest | XF:nt-writable-netbios | XF:nt-netbios-everyoneaccess-printer | XF:nt-netbios-share-print-guest  View

Page 237 of 20943, showing 5 records out of 104715 total, starting on record 1181, ending on 1185

Actions