CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1736  CVE-2000-0158  Candidate  Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon.  Modified (20000403-01)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall  Frech> XF:sco-mmdf-bo  View
1737  CVE-2000-0159  Entry  HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.        View
1738  CVE-2000-0160  Candidate  The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software"s manufacturer is Microsoft.  Modified (20000321-01)  ACCEPT(4) Baker, LeBlanc, Levy, Wall | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Christey  Christey> In a followup to Bugtraq, Juan Carlos Cuartango makes some | clarifications, specifically that the code that is executed | *must* be signed by Microsoft. | | See BUGTRAQ:20000222 MS signed softwrare privileges | | Microsoft sends some followups, including a statement that it | will include notification. | | The question is, does this belong in CVE? There is no known | means of exploitation; on the other hand, it is related | to privacy concerns. Several posts to the Bugtraq list | indicate that some people believe that unprompted installation | is a significant concern. | Frech> XF:win-active-setup | Levy> BID 999 | | I do consider this vulnerability as it allows a malicious web page | to install *old* and *vulnerable* components signed by microsoft. | LeBlanc> Fixed in MS00-042 | Christey> BID:999 | Also add XF:ie-active-setup-download ?  View
1739  CVE-2000-0161  Entry  Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.        View
1740  CVE-2000-0162  Entry  The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability.        View

Page 348 of 20943, showing 5 records out of 104715 total, starting on record 1736, ending on 1740

Actions