CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2058 | CVE-2000-0480 | Candidate | Dragon telnet server allows remote attackers to cause a denial of service via a long username. | Proposed (20000712) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(1) Christey | Christey> XF:dragon-telnet-dos | Frech> XF:dragon-ftp-dos(4691) | View |
2065 | CVE-2000-0487 | Candidate | The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability. | Proposed (20000712) | ACCEPT(3) LeBlanc, Levy, Wall | MODIFY(1) Frech | NOOP(1) Ozancin | Frech> XF:ms-protected-store(4589) | View |
2069 | CVE-2000-0491 | Candidate | Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request. | Proposed (20000712) | MODIFY(2) Frech, Levy | NOOP(2) LeBlanc, Wall | REVIEWING(2) Christey, Ozancin | Levy> The BID 1233 vulns is different from the other ones. BID 1233 uses | a FORWARD_QUERY request to overflow an in_addr structure via a memmove | in daemon/xdmcp.c, gdm_xdmcp_handle_forward_query(). In BID 1370 | a buffer is overflowed by a sprintf in xdmcp.c, send_failed(). | Frech> XF:gnome-gdm-bo(4530) | Christey> MANDRAKE:MDKSA-2001:070 | URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-070.php3 | Christey> BUGTRAQ:20000527 gdm exploit | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96017189021021&w=2 | | Consider REDHAT:RHSA-2000:027 | Christey> RHSA-2000:027 confirmed via Mark Cox | View |
2070 | CVE-2000-0492 | Candidate | PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(2) Frech, Ozancin | NOOP(2) LeBlanc, Wall | Ozancin> change "attacker who can read the password" to "attacker to decrypt and read | the password" | Frech> XF:passwd-weak-encryption(4596) | View |
2080 | CVE-2000-0503 | Candidate | The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(2) Frech, Wall | NOOP(2) LeBlanc, Ozancin | REVIEWING(1) Christey | Wall> This affects more than IE 5.01. See http://www.securityfocus.com/bid/1311 for | all versions of IE that this affects. Works on Windows 98, IE 5.01 and IE 5.5. | LeBlanc> If this is the one I was discussing offline with Steve, ACCEPT | Frech> XF:ie-cross-frame(4610) | Christey> Make sure this is the one I was discussing offline with David :-) | Frech> CVE-2000-0503 was reassigned to ie-frame-domain-file-access(5504) from | ie-cross-frame(4610), which was obsoleted and redirected to this | issue. Since these are the same issues but just described differently, | CVE-2000-0503 appears to be a dupe of CVE-2000-0768. | View |
Page 358 of 20943, showing 5 records out of 104715 total, starting on record 1786, ending on 1790