CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1706  CVE-2000-0128  Entry  The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.        View
1707  CVE-2000-0129  Candidate  Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.  Proposed (20000208)  ACCEPT(3) Baker, Blake, Cole | MODIFY(2) Frech, Levy | NOOP(2) Armstrong, Ozancin | RECAST(1) Christey | REVIEWING(1) Wall  Frech> XF:win-shortcut-api-bo | The real problem seems to be with the Windows API call, not the Serv-U FTP | app. As the "Windows Api SHGetPathFromIDList Buffer Overflow" reference | states, [The bug can] "cause whatever handles the shortcuts to crash." | As a suggestion, rephrase the description from Windows"s context, and state | that the Serv-U FTP server is an example of an app that exhibits this | problem. | Wall> Comment: the original UssrLabs advisory does mention the SHGetPathFromIDList | buffer overflow in a Windows API and that Serv-U FTP uses this API to cause the | problem. The problem does not exist on Windows 2000. The solution seems to be | in a new release of Serv-U FTP. | Levy> BID 970 | Christey> | Reports indicate that while the vulnerable function was found in Serv-U FTP | server, the function is actually from Microsoft, and as such may affect other | applications. | XF:win-shortcut-api-bo | BID:970  View
1708  CVE-2000-0130  Entry  Buffer overflow in SCO scohelp program allows remote attackers to execute commands.        View
1709  CVE-2000-0131  Entry  Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.        View
1710  CVE-2000-0132  Candidate  Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.  Proposed (20000208)  ACCEPT(2) Cole, Wall | NOOP(1) Baker | REJECT(3) Christey, Frech, LeBlanc  Frech> How is this different from MITRE:CVE-2000-0162, other than the | fact that it has an MS advisory that"s vague on the reason but | has the same outcome, and this one mentions the | getSystemResourceAsStream function? | Christey> This is a duplicate of CVE-2000-0162, as confirmed via David | LeBlanc. The descriptions of CVE-2000-0132 and CVE-2000-0162 were | significantly different, as was the descriptive text of | MS:MS00-011 and the original Bugtraq posting. So this | duplicate wasn"t picked up before. CVE-2000-0162 needs to be | modified to include XF:virtual-machine-file-read as a | reference. | LeBlanc> Duplicate | Christey> Ensure that CVE-2000-0162 uses msvm-java-file-read(4024) now, | instead of virtual-machine-file-read(4577) | Frech> If duplicate with CVE-2000-0098, shouldn"t the references be | moved over to the valid CVE number? Please advise. | Christey> When CVE-2000-0132 is rejected, the references will be added | to CVE-2000-0098.  View

Page 342 of 20943, showing 5 records out of 104715 total, starting on record 1706, ending on 1710

Actions