CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1791  CVE-2000-0213  Candidate  The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.  Proposed (20000322)  ACCEPT(6) Armstrong, Baker, Blake, Cole, Frech, Levy | NOOP(3) LeBlanc, Ozancin, Wall    View
1792  CVE-2000-0214  Candidate  FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.  Proposed (20000322)  ACCEPT(5) Armstrong, Baker, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(3) Blake, LeBlanc, Wall  Frech> XF:ftp-explorer-weak-pwd(4038)  View
1793  CVE-2000-0215  Entry  Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.        View
1794  CVE-2000-0216  Candidate  Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.  Proposed (20000322)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REJECT(3) Blake, LeBlanc, Levy | REVIEWING(1) Wall  Blake> This is a configuration issue. Should the fact that NT can be configured | to accept a blank Admin password have a CVE entry? | LeBlanc> This is documented as bad practice - if you have a wide distribution | mailing list, you should only allow certain users to send mail to it. | I don"t think we want to start listing all possible admin errors as | vulnerabilities. | Frech> XF:microsoft-mail-client-dos(4893) | Levy> I agree with all the above comments. Furthermore the delivery status | notification RFC makes it clear that mailing list software should | strip messages from DSN headers. I assume Microsoft"s products are | using the DSN standard and not something else.  View
1795  CVE-2000-0217  Entry  The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client"s X sessions via a malicious xauth program.        View

Page 359 of 20943, showing 5 records out of 104715 total, starting on record 1791, ending on 1795

Actions