CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1791 | CVE-2000-0213 | Candidate | The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters. | Proposed (20000322) | ACCEPT(6) Armstrong, Baker, Blake, Cole, Frech, Levy | NOOP(3) LeBlanc, Ozancin, Wall | View | |
1792 | CVE-2000-0214 | Candidate | FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites. | Proposed (20000322) | ACCEPT(5) Armstrong, Baker, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(3) Blake, LeBlanc, Wall | Frech> XF:ftp-explorer-weak-pwd(4038) | View |
1793 | CVE-2000-0215 | Entry | Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges. | View | |||
1794 | CVE-2000-0216 | Candidate | Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list. | Proposed (20000322) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REJECT(3) Blake, LeBlanc, Levy | REVIEWING(1) Wall | Blake> This is a configuration issue. Should the fact that NT can be configured | to accept a blank Admin password have a CVE entry? | LeBlanc> This is documented as bad practice - if you have a wide distribution | mailing list, you should only allow certain users to send mail to it. | I don"t think we want to start listing all possible admin errors as | vulnerabilities. | Frech> XF:microsoft-mail-client-dos(4893) | Levy> I agree with all the above comments. Furthermore the delivery status | notification RFC makes it clear that mailing list software should | strip messages from DSN headers. I assume Microsoft"s products are | using the DSN standard and not something else. | View |
1795 | CVE-2000-0217 | Entry | The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client"s X sessions via a malicious xauth program. | View |
Page 359 of 20943, showing 5 records out of 104715 total, starting on record 1791, ending on 1795