CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2670  CVE-2000-1103  Candidate  rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:rcvtty-elevate-privileges(5587)  View
2671  CVE-2000-1104  Candidate  Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.  Proposed (20001219)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech  Frech> XF:iis-cross-site-scripting(5156)  View
2672  CVE-2000-1105  Candidate  The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.  Proposed (20001219)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | REVIEWING(2) Christey, Wall  Frech> XF:win2k-index-service-ixsso(5502) | Christey> ADDREF MS:MS00-098 | ADDREF XF:win2k-index-service-activex | URL:http://xforce.iss.net/static/5800.php | Add "aka the "Indexing Service File Enumeration" vulnerability" | to the description. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> DUPE CVE-2001-0245? Need to check w/Microsoft.  View
2677  CVE-2000-1110  Candidate  document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:ibm-netdata-reveal-path(5599)  View
2681  CVE-2000-1114  Candidate  Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:ewave-jsp-source-read(5562)  View

Page 325 of 20943, showing 5 records out of 104715 total, starting on record 1621, ending on 1625

Actions