CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1211  CVE-1999-1231  Candidate  ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall    View
1212  CVE-1999-1232  Candidate  Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.  Modified (20060503)  ACCEPT(1) Frech | NOOP(2) Cole, Foat    View
1213  CVE-1999-1233  Entry  IIS 4.0 does not properly restrict access for the initial session request from a user"s IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability.        View
1214  CVE-1999-1234  Candidate  LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.  Proposed (20010912)  ACCEPT(3) Cole, Frech, Wall | NOOP(1) Foat    View
1215  CVE-1999-1235  Candidate  Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user"s index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.  Proposed (20010912)  ACCEPT(4) Cole, Foat, Frech, Wall  CHANGE> [Foat changed vote from NOOP to ACCEPT]  View

Page 243 of 20943, showing 5 records out of 104715 total, starting on record 1211, ending on 1215

Actions