CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1636  CVE-2000-0058  Candidate  Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.  Proposed (20000125)  MODIFY(2) Baker, Frech | NOOP(1) Christey  Frech> XF:handspring-visor-auth(3873) | Consider removing the security-express.com reference, since it is identical | to the BugTraq reference. The BugTraq reference is (hopefully) not going to | disappear soon, and the security-express.com reference provides no new or | additional information. | Christey> URLs will begin to be included with candidates to support | Board members" voting activities. They will be converted to | the generalized reference format when if candidate is | ACCEPTed and becomes an official entry. | Christey> The problem may not be a lack of authentication (as mentioned | by the poster), but rather weak authentication (the apparent | need to provide the same username). | Baker> MOdify description to indicate the weak authentication  View
1637  CVE-2000-0059  Candidate  PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.  Proposed (20000125)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:php3-popen-execute(3900) | Christey> CONFIRM:http://www.php.net/ChangeLog.php3 | Section dated January 11, 2000 says: "Fix safe-mode problem in | popen() (Kristian)"  View
1638  CVE-2000-0060  Entry  Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.        View
1639  CVE-2000-0061  Candidate  Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.  Proposed (20000125)  MODIFY(2) Frech, LeBlanc | NOOP(1) Baker | REJECT(1) Christey  Frech> XF:ie-cross-frame-docs(3901) | LeBlanc> - I"d like to see a KB or bulletin referenced | Christey> This is a duplicate of CVE-2000-0156. The FAQ at | http://www.microsoft.com/technet/security/bulletin/fq00-009.asp. | says "the vulnerability requires Active Scripting" and | "it is possible, under very specific conditions, to violate IE"s | cross-domain security model." Also says "the redirect is made, via | the <IMG SRC> HTML tag" | | Need to copy these references over to CVE-2000-0156.  View
1640  CVE-2000-0062  Entry  The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.        View

Page 328 of 20943, showing 5 records out of 104715 total, starting on record 1636, ending on 1640

Actions