CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2225  CVE-2000-0649  Candidate  IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.  Proposed (20000803)  ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(2) Christey, Wall  Christey> ADDREF http://support.microsoft.com/support/kb/articles/Q218/1/80.ASP | | Change description to point out that the internal IP address | exposure is due to the default configuration as opposed to | a bug. | Frech> XF:iis-internal-ip-disclosure(5106) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> There are two variants of the same type of issue here. The | KB article shows that IIS 4.0 reveals the IP address in a | Content-Location MIME header field. The NTBugtraq article | says that the IP address is shown in the WWW-Authenticate | MIME header. Which one has been fixed, or both, and when? | Christey> MSKB:Q218180 identifies a problem in which IIS returns the | info in a Content-Location header, but the authentication | realm problem is not specifically mentioned. Are these the | same problem?  View
2229  CVE-2000-0653  Candidate  Microsoft Outlook Express allows remote attackers to monitor a user"s email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.  Proposed (20000803)  ACCEPT(3) Cole, Levy, Wall | NOOP(1) LeBlanc | REJECT(1) Frech | REVIEWING(1) Christey  Frech> Is this a duplicate of CVE-2000-0105? I can find no differentiating evidence | to show that this issue is unique. | Christey> I need to look through my email logs to recall whether I | resolved this potential duplicate with Microsoft people. | CHANGE> [Frech changed vote from REVIEWING to REJECT]  View
2232  CVE-2000-0656  Candidate  Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol.  Proposed (20000803)  ACCEPT(1) Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall  Frech> XF:analogx-proxy-ftp-crash(4981)  View
2233  CVE-2000-0657  Candidate  Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.  Proposed (20000803)  ACCEPT(1) Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall  Frech> XF:analogx-proxy-smtp-helo(5164)  View
2234  CVE-2000-0658  Candidate  Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.  Proposed (20000803)  ACCEPT(1) Levy | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall  Frech> XF:analogx-proxy-pop3-crash(4982)  View

Page 353 of 20943, showing 5 records out of 104715 total, starting on record 1761, ending on 1765

Actions