CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1844 | CVE-2000-0266 | Candidate | Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL. | Proposed (20000426) | ACCEPT(5) Baker, Cole, LeBlanc, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:ie-java-crossframe-security | Christey> May be a duplicate of CVE-2000-0465 according to my | communications with Microsoft people. CVE-2000-0028 may | also be a variant. | LeBlanc> MS00-039 | View |
1847 | CVE-2000-0269 | Candidate | Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess. | Proposed (20000426) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> ADDREF XF:emacs-local-eavesdrop | Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | Frech> XF:emacs-local-eavesdrop | Christey> ADDREF MANDRAKE:MDKSA-2000:088 ? | Also http://www.securityfocus.com/bid/2164, but is that a | duplicate of BID:1125? | View |
1848 | CVE-2000-0270 | Candidate | The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack. | Proposed (20000426) | ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall | Christey> ADDREF XF:emacs-tempfile-creation | Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | Frech> XF:emacs-tempfile-creation | Levy> Change BID reference to BID 1126 | View |
1849 | CVE-2000-0271 | Candidate | read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords. | Proposed (20000426) | ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall | Christey> Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | ADDREF XF:emacs-password-history | Frech> XF:emacs-password-history | Levy> Change BID reference to BID 1127 | View |
1853 | CVE-2000-0275 | Candidate | CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user"s PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN. | Proposed (20000426) | ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:cryptoadmin-weak-encryption | View |
Page 368 of 20943, showing 5 records out of 104715 total, starting on record 1836, ending on 1840