CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1731  CVE-2000-0153  Candidate  FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.  Proposed (20000223)  ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) LeBlanc  LeBlanc> I think this is the same as | http://www.microsoft.com/technet/security/bulletin/ms99-010.asp | If that is true, and you already have it logged, we don"t want to have an | entry for the same bug. | Christey> MS:MS99-010 describes CVE-1999-0386. Are there sufficient | details to ensure that this is the same problem? | | See http://www.securityfocus.com/templates/archive.pike?list=1&msg=01bae51a$9ab232b0$0100007f@nordnode | | Frech> XF:pws-file-access | (We currently have this issue assigned to this CAN and to CVE-1999-0386. I | see that others have similar concerns that this is a duplicate; please | confirm on current status of this candidate.) | Christey> [note to self: review comments by Mark Burnett]  View
1732  CVE-2000-0154  Candidate  The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.  Modified (20000403-01)  ACCEPT(1) Cole | NOOP(3) Baker, LeBlanc, Wall | REJECT(3) Christey, Frech, Levy  Christey> DUPE CVE-2000-0224 | Frech> DUPE MITRE:CVE-2000-0224; XF:sco-openserver-arc-symlink | Recommend moving BID reference to CVE-2000-0224.  View
1733  CVE-2000-0155  Candidate  Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.  Proposed (20000223)  ACCEPT(4) Baker, Cole, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:nt-autorun-notdefault | Christey> Consider: | http://support.microsoft.com/support/kb/articles/Q155/2/17.asp | http://support.microsoft.com/support/kb/articles/Q136/2/14.asp  View
1734  CVE-2000-0156  Entry  Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability.        View
1735  CVE-2000-0157  Entry  NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.        View

Page 347 of 20943, showing 5 records out of 104715 total, starting on record 1731, ending on 1735

Actions