CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2322 | CVE-2000-0746 | Candidate | Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities. | Proposed (20000921) | ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> Make sure both BID"s are appropriate | XF:iis-cross-site-scripting | http://xforce.iss.net/static/5156.php | Frech> XF: iis-cross-site-scripting(5156) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> A re-release of MS:MS00-060 indicates that a new variant of | this problem was discovered, but the advisory does not | provide sufficient details to distinguish it from this | candidate. A new candidate is being created, but the | description can"t be written without mentioning this CAN. | View |
2324 | CVE-2000-0748 | Candidate | OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse. | Proposed (20000921) | ACCEPT(1) Levy | NOOP(4) Baker, Cole, Wall, Williams | View | |
2328 | CVE-2000-0752 | Candidate | Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments. | Proposed (20000921) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:freebsd-brouted-bo(6185) | View |
2331 | CVE-2000-0755 | Candidate | Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges. | Proposed (20000921) | ACCEPT(2) Cole, Levy | NOOP(2) Baker, Wall | REJECT(2) Christey, Frech | Christey> DUPE CVE-2000-0730 | Also, the BID is wrong. | Frech> DUPE OF CVE-2000-0730 | Also, the BID is wrong. | View |
2332 | CVE-2000-0756 | Candidate | Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(2) Frech, LeBlanc | REVIEWING(2) Christey, Wall | LeBlanc> - if a KB article, bulletin, or patch can be found, then | I"ll ACCEPT | Christey> This is the same as MS:MS01-012 (CVE-2001-0145) | See the Bugtraq post by Joel Moses: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Frech> XF:outlook-vcard-dos(5175) | XF:outlook-vcard-bo(6145) | Because there"s another more recent CAN linked to @stake and | Microsoft"s advisories, we"ll link both of our records to both | candiates until a final decision occurs. If a decision has been made | to promote the CVE-2001 entry, then enter my vote as a REJECT for | CVE-2000-0756. | Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175) | View |
Page 345 of 20943, showing 5 records out of 104715 total, starting on record 1721, ending on 1725