CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1706 | CVE-2000-0128 | Entry | The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters. | View | |||
1707 | CVE-2000-0129 | Candidate | Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file. | Proposed (20000208) | ACCEPT(3) Baker, Blake, Cole | MODIFY(2) Frech, Levy | NOOP(2) Armstrong, Ozancin | RECAST(1) Christey | REVIEWING(1) Wall | Frech> XF:win-shortcut-api-bo | The real problem seems to be with the Windows API call, not the Serv-U FTP | app. As the "Windows Api SHGetPathFromIDList Buffer Overflow" reference | states, [The bug can] "cause whatever handles the shortcuts to crash." | As a suggestion, rephrase the description from Windows"s context, and state | that the Serv-U FTP server is an example of an app that exhibits this | problem. | Wall> Comment: the original UssrLabs advisory does mention the SHGetPathFromIDList | buffer overflow in a Windows API and that Serv-U FTP uses this API to cause the | problem. The problem does not exist on Windows 2000. The solution seems to be | in a new release of Serv-U FTP. | Levy> BID 970 | Christey> | Reports indicate that while the vulnerable function was found in Serv-U FTP | server, the function is actually from Microsoft, and as such may affect other | applications. | XF:win-shortcut-api-bo | BID:970 | View |
1708 | CVE-2000-0130 | Entry | Buffer overflow in SCO scohelp program allows remote attackers to execute commands. | View | |||
1709 | CVE-2000-0131 | Entry | Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands. | View | |||
1710 | CVE-2000-0132 | Candidate | Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function. | Proposed (20000208) | ACCEPT(2) Cole, Wall | NOOP(1) Baker | REJECT(3) Christey, Frech, LeBlanc | Frech> How is this different from MITRE:CVE-2000-0162, other than the | fact that it has an MS advisory that"s vague on the reason but | has the same outcome, and this one mentions the | getSystemResourceAsStream function? | Christey> This is a duplicate of CVE-2000-0162, as confirmed via David | LeBlanc. The descriptions of CVE-2000-0132 and CVE-2000-0162 were | significantly different, as was the descriptive text of | MS:MS00-011 and the original Bugtraq posting. So this | duplicate wasn"t picked up before. CVE-2000-0162 needs to be | modified to include XF:virtual-machine-file-read as a | reference. | LeBlanc> Duplicate | Christey> Ensure that CVE-2000-0162 uses msvm-java-file-read(4024) now, | instead of virtual-machine-file-read(4577) | Frech> If duplicate with CVE-2000-0098, shouldn"t the references be | moved over to the valid CVE number? Please advise. | Christey> When CVE-2000-0132 is rejected, the references will be added | to CVE-2000-0098. | View |
Page 342 of 20943, showing 5 records out of 104715 total, starting on record 1706, ending on 1710