CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2322  CVE-2000-0746  Candidate  Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.  Proposed (20000921)  ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Christey> Make sure both BID"s are appropriate | XF:iis-cross-site-scripting | http://xforce.iss.net/static/5156.php | Frech> XF: iis-cross-site-scripting(5156) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> A re-release of MS:MS00-060 indicates that a new variant of | this problem was discovered, but the advisory does not | provide sufficient details to distinguish it from this | candidate. A new candidate is being created, but the | description can"t be written without mentioning this CAN.  View
2324  CVE-2000-0748  Candidate  OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.  Proposed (20000921)  ACCEPT(1) Levy | NOOP(4) Baker, Cole, Wall, Williams    View
2328  CVE-2000-0752  Candidate  Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.  Proposed (20000921)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:freebsd-brouted-bo(6185)  View
2331  CVE-2000-0755  Candidate  Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.  Proposed (20000921)  ACCEPT(2) Cole, Levy | NOOP(2) Baker, Wall | REJECT(2) Christey, Frech  Christey> DUPE CVE-2000-0730 | Also, the BID is wrong. | Frech> DUPE OF CVE-2000-0730 | Also, the BID is wrong.  View
2332  CVE-2000-0756  Candidate  Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(2) Frech, LeBlanc | REVIEWING(2) Christey, Wall  LeBlanc> - if a KB article, bulletin, or patch can be found, then | I"ll ACCEPT | Christey> This is the same as MS:MS01-012 (CVE-2001-0145) | See the Bugtraq post by Joel Moses: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Frech> XF:outlook-vcard-dos(5175) | XF:outlook-vcard-bo(6145) | Because there"s another more recent CAN linked to @stake and | Microsoft"s advisories, we"ll link both of our records to both | candiates until a final decision occurs. If a decision has been made | to promote the CVE-2001 entry, then enter my vote as a REJECT for | CVE-2000-0756. | Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175)  View

Page 345 of 20943, showing 5 records out of 104715 total, starting on record 1721, ending on 1725

Actions