CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1688 | CVE-2000-0110 | Candidate | The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | Proposed (20000208) | ACCEPT(1) Baker | MODIFY(1) Frech | RECAST(1) Cole | REVIEWING(1) Wall | Cole> See comments for CVE-2000-0101 | Frech> XF:shopping-cart-form-tampering | View |
1692 | CVE-2000-0114 | Candidate | Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory. | Proposed (20000208) | ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:iis-frontpage-info | Christey> Acknowledged via personal communication with Microsoft | personnel. | | May be the same as BID:1174 and/or BID:1433 (both mention | FrontPage, but one mentions shtml.exe and another mentions | shtml.dll) | Christey> [note to self: review comments by Mark Burnett] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
1693 | CVE-2000-0115 | Candidate | IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page. | Proposed (20000208) | ACCEPT(1) Cole | NOOP(1) Baker | REJECT(2) Frech, LeBlanc | REVIEWING(1) Wall | Frech> This reference to NTBugtraq has a message that ends with "Can anyone | reproduce this?", and there are no followups. This makes for a weak | reference. There are also no other references listed for this CAN. | LeBlanc> - no follow-ups, no KB article, no fix | CHANGE> [Frech changed vote from REVIEWING to REJECT] | View |
1696 | CVE-2000-0118 | Candidate | The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing. | Proposed (20000208) | ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> Is this the same issue as BugTraq Mailing List, Wed, 9 Jun 1999 14:07:27 | -0700 "vulnerability in su/PAM in redhat" at | http://www.netspace.org/cgi-bin/wa?A2=ind9906b&L=bugtraq&F=&S=&P=5356 and | "Solaris 2.5 /bin/su [was: vulnerability in su/PAM in redhat]" at | http://www.netspace.org/cgi-bin/wa?A2=ind9906b&L=bugtraq&F=&S=&P=6051 | If so, then MODIFY XF:su-brute | Christey> BID:320 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=320 | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:su-brute(2278) | This issue involves more platforms than Red Hat. See BugTraq | Mailing List, Thu Jun 10 1999 12:13:06, "Solaris 2.5 /bin/su [was: | vulnerability in su/PAM in redhat]", | http://www.securityfocus.com/archive/1/14854 | Christey> It does look like this is the same issue as the other Bugtraq | post that explicitly mentions Red Hat and PAM. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
1697 | CVE-2000-0119 | Candidate | The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection. | Proposed (20000208) | ACCEPT(2) Cole, Wall | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Christey | Christey> ADDREF BID:956 | | A followup post on Feb 8 by Paul L Schmehl claims that this | would not work, because the anti-virus checkers would | activate if the user attempts to execute the program. | Frech> XF:win-trojan-detection-bypass | Much earlier possible reference at NTBugtraq Mailing List, Wed, 22 Dec 1999 | 20:37:43 -0800, "Bypass Virus Checking under 95/98/NT" at | http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9912&L=ntbugtraq&F=&S=&P=6030 | CHANGE> [Cole changed vote from REVIEWING to ACCEPT] | Christey> NTBUGTRAQ:19991222 Bypass Virus Checking under 95/98/NT | http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9912&L=ntbugtraq&F=&S=&P=6030 | View |
Page 378 of 20943, showing 5 records out of 104715 total, starting on record 1886, ending on 1890