CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1876  CVE-2000-0298  Entry  The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.        View
1877  CVE-2000-0299  Candidate  Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.  Proposed (20000426)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Williams | REVIEWING(1) Levy  Christey> ADDREF XF:webobjects-post-dos | Frech> XF:webobjects-post-dos | Christey> See http://til.info.apple.com/techinfo.nsf/artnum/n75087 | Document says: | "A request with a large, malformed http header can crash a WOApp" | (Apple reference #2470254) appears to be the acknowledgement needed. | | Is this sufficient acknowledgement? This is dated AUgust 24, | but the initial disclosure occurred on April 4. | Christey> BID:1896  View
1878  CVE-2000-0300  Candidate  The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.  Proposed (20000426)  ACCEPT(4) Baker, Cole, Levy, Prosser | MODIFY(1) Frech | REVIEWING(1) Wall  Frech> XF:pcanywhere-weak-encryption | Prosser> http://service2.symantec.com/SUPPORT/pca.nsf/pfdocs/1999022312571812 | Upgraded in pcA 10  View
1879  CVE-2000-0301  Entry  Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.        View
1880  CVE-2000-0302  Entry  Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.        View

Page 376 of 20943, showing 5 records out of 104715 total, starting on record 1876, ending on 1880

Actions