CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3082 | CVE-2001-0261 | Candidate | Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files. | Proposed (20010404) | ACCEPT(3) Baker, Bishop, Frech | NOOP(3) Christey, Cole, Ziese | REJECT(1) LeBlanc | REVIEWING(1) Wall | Bishop> Sounds like Microsoft just confirmed it! | Christey> The description should make the point that the original files | are in plaintext. | LeBlanc> The preconditions needed to obtain the clear-text backup file | are that the user must be able to read the raw disk. Only administrators | or those with physical access can read the raw disk. An admin could | alter the operating system such that anything a user did would be | available, even EFS information (since the admin can cause processes to | run as any user who is logged on currently). Thus even if this issue | were not present, the same set of preconditions would lead to access to | the same information. In the case of physical access, scrubbing the disk | should be viewed only as raising the bar - information can be recovered | even from overwritten sectors. Additionally, coverage of a file might | not be complete - in the case where a file is truncated, then encrypted, | there could be sectors with file information that the operating system | would have no knowledge of at the time the encryption occurred, and | there is no practical way to wipe these. Considering all the realities | of the situation, the only real-world solution is to create files you"d | like encrypted in a directory marked for encryption. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT] | View |
3091 | CVE-2001-0270 | Candidate | Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set. | Proposed (20010404) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:asx-remote-dos(6133) | Christey> A rediscovery or closely related vulnerability is in CVE-2001-0994. | View |
3093 | CVE-2001-0272 | Candidate | Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter. | Proposed (20010404) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:sendtemp-pl-read-files(6104) | Amaya, not Anaya | View |
3096 | CVE-2001-0275 | Candidate | Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request. | Proposed (20010404) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:moby-netsuite-bo(6132) | View |
3098 | CVE-2001-0277 | Candidate | Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request. | Proposed (20010404) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> XF:badblue-ext-dos(6131) | Christey> CONFIRM:http://www.badblue.com/p010219.htm | View |
Page 300 of 20943, showing 5 records out of 104715 total, starting on record 1496, ending on 1500