CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3082  CVE-2001-0261  Candidate  Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.  Proposed (20010404)  ACCEPT(3) Baker, Bishop, Frech | NOOP(3) Christey, Cole, Ziese | REJECT(1) LeBlanc | REVIEWING(1) Wall  Bishop> Sounds like Microsoft just confirmed it! | Christey> The description should make the point that the original files | are in plaintext. | LeBlanc> The preconditions needed to obtain the clear-text backup file | are that the user must be able to read the raw disk. Only administrators | or those with physical access can read the raw disk. An admin could | alter the operating system such that anything a user did would be | available, even EFS information (since the admin can cause processes to | run as any user who is logged on currently). Thus even if this issue | were not present, the same set of preconditions would lead to access to | the same information. In the case of physical access, scrubbing the disk | should be viewed only as raising the bar - information can be recovered | even from overwritten sectors. Additionally, coverage of a file might | not be complete - in the case where a file is truncated, then encrypted, | there could be sectors with file information that the operating system | would have no knowledge of at the time the encryption occurred, and | there is no practical way to wipe these. Considering all the realities | of the situation, the only real-world solution is to create files you"d | like encrypted in a directory marked for encryption. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT]  View
3091  CVE-2001-0270  Candidate  Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.  Proposed (20010404)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:asx-remote-dos(6133) | Christey> A rediscovery or closely related vulnerability is in CVE-2001-0994.  View
3093  CVE-2001-0272  Candidate  Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.  Proposed (20010404)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:sendtemp-pl-read-files(6104) | Amaya, not Anaya  View
3096  CVE-2001-0275  Candidate  Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.  Proposed (20010404)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:moby-netsuite-bo(6132)  View
3098  CVE-2001-0277  Candidate  Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.  Proposed (20010404)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:badblue-ext-dos(6131) | Christey> CONFIRM:http://www.badblue.com/p010219.htm  View

Page 300 of 20943, showing 5 records out of 104715 total, starting on record 1496, ending on 1500

Actions