CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
547 | CVE-1999-0561 | Candidate | IIS has the #exec function enabled for Server Side Include (SSI) files. | Proposed (19990728) | NOOP(2) Baker, Northcutt | RECAST(1) Shostack | REJECT(1) LeBlanc | LeBlanc> Does not meet definition of a vulnerability. This function is | just enabled. You can turn it off if you want. if you trust the people | putting up your web pages, this isn"t a problem. If you don"t, this is | just one of many things you need to change. | View |
1978 | CVE-2000-0400 | Candidate | The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user"s system by encoding it within an email message or news post. | Proposed (20000615) | ACCEPT(4) Frech, Levy, Ozancin, Wall | NOOP(2) Cole, Stracener | REJECT(1) Christey | REVIEWING(1) LeBlanc | LeBlanc> COMMENT - this definately will not work if the user has applied the security | patch. I don"t know whether this repros right now, and have sent a query to | find out. | Christey> Is this now documented in MS:MS00-042? | LeBlanc> the problem isn"t in the Active Movie control. What was | observed was a symptom of another problem that got fixed in | some bulletin or another - I don"t remember. | Christey> According to Scott Culp, this existed because | the patch for the Cache Bypass vulnerability (MS:MS00-046, | CVE-2000-0621) was not applied, so this should be REJECTed | as a duplicate of CVE-2000-0621. | View |
1903 | CVE-2000-0325 | Candidate | The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. | Modified (20020222-01) | ACCEPT(5) Armstrong, Baker, Cole, Prosser, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc | REVIEWING(1) Christey | LeBlanc> - same as CVE-1999-1011 | If I"m misunderstanding something here, please correct me. In fact, it has | the same bulletin as a reference. | Frech> XF:jet-vba-shell | Prosser> This entry is not the same as "now" CVE-1999-1011. That entry is "The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands." This one should be correct. | Christey> BUGTRAQ:19990525 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=bugtraq&m=92765973107637&w=2 | NTBUGTRAQ:19990526 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=ntbugtraq&m=92781907215748&w=2 | Christey> The Microsoft advisory itself describes two separate | vulnerabilities, calling the TEXT I-ISAM problem | (CVE-2000-0323) a variant of the VBA Shell problem (this | CAN). In addition, CVE-2000-0323 does *not* appear in Jet | 4.0, while this one does. Since one problem appears in a | different version than the other, CD:SF-LOC suggests keeping | these candidates SPLIT. | | BID:548 | http://www.securityfocus.com/bid/548 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Need to clarify whether the Bugtraq/NTBugtraq posts are | really describing the same issue (those are BID:286). | View |
2332 | CVE-2000-0756 | Candidate | Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(2) Frech, LeBlanc | REVIEWING(2) Christey, Wall | LeBlanc> - if a KB article, bulletin, or patch can be found, then | I"ll ACCEPT | Christey> This is the same as MS:MS01-012 (CVE-2001-0145) | See the Bugtraq post by Joel Moses: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Frech> XF:outlook-vcard-dos(5175) | XF:outlook-vcard-bo(6145) | Because there"s another more recent CAN linked to @stake and | Microsoft"s advisories, we"ll link both of our records to both | candiates until a final decision occurs. If a decision has been made | to promote the CVE-2001 entry, then enter my vote as a REJECT for | CVE-2000-0756. | Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175) | View |
3007 | CVE-2001-0186 | Candidate | Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Proposed (20010309) | MODIFY(1) Frech | NOOP(2) Lawler, Ziese | Lawler> Very little info available. | Frech> XF:free-java-directory-traversal(6064) | View |
Page 35 of 20943, showing 5 records out of 104715 total, starting on record 171, ending on 175