CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6878  CVE-2003-0049  Candidate  Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.  Modified (20071022)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall  Baker> Realizing they have acknowledged the problem, and provided a fix by allowing the administrator to select whether or not this is allowed, | I am not sure this should really be a vulnerability. If you are the administrator on a system, there are other ways I can become a user | on a system. The fact that you are the administrator (root) you can do almost anything to the system you want, including accessing files | and programs that belong to other users. From a security standpoint, if the system gets "hacked" and the administrator account is compromised, | how big of an issue is it really that the administrator can now access regular user accounts with the administrator password? I am not sure this | should really be a vulnerability. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT]  View
2369  CVE-2000-0793  Candidate  Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system.  Proposed (20000921)  ACCEPT(1) Levy | MODIFY(1) Baker | NOOP(3) Cole, Wall, Williams  Baker> Perhaps the description should read "... after the first user to log on to the system logs off."  View
3390  CVE-2001-0577  Candidate  recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.  Modified (20020225-01)  ACCEPT(2) Frech, Williams | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker | REVIEWING(1) Bishop  Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem.  View
3915  CVE-2001-1111  Candidate  EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.  Proposed (20020315)  ACCEPT(3) Baker, Frech, Green | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese  Baker> It looks like this issue was modified in the changelog, but the basic issue | still exists. They moved all data files into the ini file. Still a | plain text file, however. It would have been better in a registry setting | so it was harder to get to... | | 2.0.8.345 2001.12.04 | Fixed a problem where the server would give a GPF whn disconnecting a single user | Added Ratios Feature | Added Statistics Feature | Modified User/Group Administration - now much more stable | Modified Startup Logo | Modifed all data files to .ini files for easy editing and to save space | Added Feature to save/load queues | Added auto reconnect feature on timeout | Fully Implemented RSA Control Port encryption, so now even commands like USER, PASS, GET, REST etc are encrypted. Total security on both data and commands. | Added Idle Timout for the Server component | Fixed some security flaws with directory listings  View
3520  CVE-2001-0712  Candidate  The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.  Proposed (20011012)  ACCEPT(2) Baker, Cole | NOOP(1) Armstrong | REJECT(2) Foat, Frech | REVIEWING(1) Wall  Baker> I would argue that a browser executing a script when it shouldn"t is still a vulnerability. If it is supposed to be a non-scriptable file type, and that fails, resulting in a script being executed without the user"s knowledge, then it is a problem, and thus should be included as a vulnerability. I vote this should be accepted, and if Microsoft acknowledges this in their follow up, then you have vendor acknowledgement of the problem as well. | Foat> The candidate does not meet the criteria for a vulnerability or | exposure, even though it describes an unexpected behavior.  View

Page 366 of 20943, showing 5 records out of 104715 total, starting on record 1826, ending on 1830

Actions