CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1493 | CVE-1999-1513 | Candidate | Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities. | Proposed (20010912) | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech | Frech> (ACCEPT; Task 2355) | View |
3740 | CVE-2001-0934 | Candidate | Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname. | Proposed (20020131) | ACCEPT(1) Foat | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Wall | Frech> (ACCEPT; Task 2353) | Christey> Rediscovered in: | BUGTRAQ:20020211 PowerFTP Personal FTP Server Multiple Vulnerabilities | http://marc.theaimsgroup.com/?l=bugtraq&m=101361745222207&w=2 | This rediscovery says the problem is in 2.10. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:powerftp-pwd-path-disclosure(8182) | Christey> BID:4072 | URL:http://online.securityfocus.com/bid/4072 | View |
3725 | CVE-2001-0919 | Candidate | Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript. | Modified (20040811) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall | Frech> (ACCEPT: Task 2352) | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ie-cookie-prompt-bypass(8621) | Christey> Add period to the end of the description. | View |
98 | CVE-1999-0098 | Candidate | Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities. | Proposed (19990726) | MODIFY(2) Baker, Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> (Accept XF reference.) | Our references do not mention hiding activities. This issue can crash the | SMTP server or execute arbitrary byte-code. Is there another reference | available? | Christey> Should this be merged with CVE-1999-0284, which is Sendmail | with SMTP HELO? | Christey> BUGTRAQ:19980522 about sendmail 8.8.8 HELO hole | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925991&w=2 | BUGTRAQ:19980527 about sendmail 8.8.8 HELO hole | http://marc.theaimsgroup.com/?l=bugtraq&m=90221101926003&w=2 | Baker> Apparently this XF reference is not for this issue, but for the other issue. This should be modified to have the Bugtraq references, and remove the XF reference. | View |
283 | CVE-1999-0284 | Candidate | Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. | Proposed (19990623) | ACCEPT(2) Blake, Northcutt | MODIFY(3) Frech, Levy, Ozancin | NOOP(1) Baker | REVIEWING(1) Christey | Frech> "Windows NT-based mail servers" (A trademark thing, and for clarification) | XF:mdaemon-helo-bo | XF:lotus-notes-helo-crash | XF:slmail-helo-overflow | XF:smtp-helo-bo (mentions several products) | XF:smtp-exchangedos | Levy> - Need one per software. Each one should be its own | vulnerability. | Ozancin> => Windows NT is correct | Christey> These are probably multiple codebases, so we"ll need to use | dot notation. Also need to see if this should be merged | with CVE-1999-0098 (Sendmail SMTP HELO). | View |
Page 245 of 20943, showing 5 records out of 104715 total, starting on record 1221, ending on 1225