CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1844  CVE-2000-0266  Candidate  Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.  Proposed (20000426)  ACCEPT(5) Baker, Cole, LeBlanc, Levy, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:ie-java-crossframe-security | Christey> May be a duplicate of CVE-2000-0465 according to my | communications with Microsoft people. CVE-2000-0028 may | also be a variant. | LeBlanc> MS00-039  View
1847  CVE-2000-0269  Candidate  Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.  Proposed (20000426)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> ADDREF XF:emacs-local-eavesdrop | Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | Frech> XF:emacs-local-eavesdrop | Christey> ADDREF MANDRAKE:MDKSA-2000:088 ? | Also http://www.securityfocus.com/bid/2164, but is that a | duplicate of BID:1125?  View
1848  CVE-2000-0270  Candidate  The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.  Proposed (20000426)  ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall  Christey> ADDREF XF:emacs-tempfile-creation | Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | Frech> XF:emacs-tempfile-creation | Levy> Change BID reference to BID 1126  View
1849  CVE-2000-0271  Candidate  read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.  Proposed (20000426)  ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall  Christey> Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | ADDREF XF:emacs-password-history | Frech> XF:emacs-password-history | Levy> Change BID reference to BID 1127  View
1853  CVE-2000-0275  Candidate  CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user"s PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.  Proposed (20000426)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:cryptoadmin-weak-encryption  View

Page 368 of 20943, showing 5 records out of 104715 total, starting on record 1836, ending on 1840

Actions