CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1798 | CVE-2000-0220 | Candidate | ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event. | Proposed (20000322) | ACCEPT(1) Armstrong | MODIFY(1) Frech | NOOP(5) Baker, Cole, LeBlanc, Ozancin, Wall | REJECT(1) Blake | REVIEWING(1) Levy | Blake> Discussion on Bugtraq shows that this is a really marginal issue. Very | tough to come up with a viable attack scenario. Also, it"s part of how | this class of software works, not a flaw in the cited package. Might be | possible to recast this into something more generic.... | Frech> XF:zonealarm-exposes-info | View |
1751 | CVE-2000-0173 | Candidate | Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service. | Proposed (20000322) | ACCEPT(3) Baker, Blake, Cole | MODIFY(1) Frech | NOOP(4) LeBlanc, Ozancin, Prosser, Wall | REVIEWING(2) Christey, Levy | Prosser> Although SCO is reporting the problem, there is too little info | available to make an informed decision. Unable to find anything | anywhere on this. It is an events logging system, so one would assume | that there is a way to fill up the log and cause a system halt, but no | way of confirming this with limited information. | Christey> Perhaps we should create a content decision, say | CD:VAGUE-ACK, which says whether it"s reasonable to | ACCEPT vendor-acknowledged problems that do not provide any | salient details, as in this candidate as well as several | others. | Cole> I researched this a little more and you can change my NOOP to an | ACCEPT | Frech> XF:sco-eels-dos | View |
1754 | CVE-2000-0176 | Candidate | The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist. | Proposed (20000322) | ACCEPT(4) Blake, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(3) Baker, LeBlanc, Wall | Frech> XF:servu-ftp-server-path(4060) | View |
1755 | CVE-2000-0177 | Candidate | DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters. | Proposed (20000322) | ACCEPT(4) Blake, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(3) Baker, LeBlanc, Wall | Frech> XF:dnstools-invalid-input(4876) | View |
1765 | CVE-2000-0187 | Candidate | EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters. | Proposed (20000322) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(6) Baker, Blake, Christey, Cole, LeBlanc, Wall | Christey> Since EZShopper is written in Perl, there is strong evidence | that both the .. and metacharacter attack probably go | through the same insecure open() call. (Perl"s open can | either read a regular file, or read piped output from | a command that is specified to the open). | Frech> XF:ezshopper-loadpage-cgi(4044) | View |
Page 372 of 20943, showing 5 records out of 104715 total, starting on record 1856, ending on 1860