CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2225 | CVE-2000-0649 | Candidate | IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined. | Proposed (20000803) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(2) Christey, Wall | Christey> ADDREF http://support.microsoft.com/support/kb/articles/Q218/1/80.ASP | | Change description to point out that the internal IP address | exposure is due to the default configuration as opposed to | a bug. | Frech> XF:iis-internal-ip-disclosure(5106) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> There are two variants of the same type of issue here. The | KB article shows that IIS 4.0 reveals the IP address in a | Content-Location MIME header field. The NTBugtraq article | says that the IP address is shown in the WWW-Authenticate | MIME header. Which one has been fixed, or both, and when? | Christey> MSKB:Q218180 identifies a problem in which IIS returns the | info in a Content-Location header, but the authentication | realm problem is not specifically mentioned. Are these the | same problem? | View |
2377 | CVE-2000-0801 | Candidate | Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option. | Proposed (20000921) | ACCEPT(3) Baker, Levy, Williams | NOOP(3) Christey, Cole, Wall | Christey> ADDREF HP:HPSBUX0010-127?? | http://archives.neohapsis.com/archives/hp/2000-q4/0028.html | View |
1862 | CVE-2000-0284 | Candidate | Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands. | Proposed (20000426) | ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> ADDREF FREEBSD:FreeBSD-SA-00:14 | URL:http://www.securityfocus.com/templates/advisory.html?id=2179 | Frech> XF:imap-mailserver-bo | View |
2022 | CVE-2000-0444 | Candidate | HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000. | Proposed (20000615) | ACCEPT(4) Frech, Levy, Prosser, Stracener | NOOP(2) Cole, Wall | REVIEWING(1) Christey | Christey> ADDREF CONFIRM:http://www.hp.com/cposupport/networking/support_doc/bpj06522.html | Christey> HP:HPSBUX0006-116 ? | XF:jetadmin-network-dos | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Prosser> Vendor acknowledged in HP Bulletin HPSBUX0006-116 with upgrade info. | View |
572 | CVE-1999-0590 | Candidate | A system does not present an appropriate legal message or warning to a user who is accessing it. | Proposed (19990728) | ACCEPT(2) Baker, Northcutt | MODIFY(1) Christey | RECAST(1) Shostack | Christey> ADDREF CIAC:J-043 | URL:http://ciac.llnl.gov/ciac/bulletins/j-043.shtml | Also add "banner" to the description to facilitate search. | Baker> Should be in place where ever it is possible | View |
Page 335 of 20943, showing 5 records out of 104715 total, starting on record 1671, ending on 1675