CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1688  CVE-2000-0110  Candidate  The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.  Proposed (20000208)  ACCEPT(1) Baker | MODIFY(1) Frech | RECAST(1) Cole | REVIEWING(1) Wall  Cole> See comments for CVE-2000-0101 | Frech> XF:shopping-cart-form-tampering  View
1692  CVE-2000-0114  Candidate  Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.  Proposed (20000208)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:iis-frontpage-info | Christey> Acknowledged via personal communication with Microsoft | personnel. | | May be the same as BID:1174 and/or BID:1433 (both mention | FrontPage, but one mentions shtml.exe and another mentions | shtml.dll) | Christey> [note to self: review comments by Mark Burnett] | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
1693  CVE-2000-0115  Candidate  IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.  Proposed (20000208)  ACCEPT(1) Cole | NOOP(1) Baker | REJECT(2) Frech, LeBlanc | REVIEWING(1) Wall  Frech> This reference to NTBugtraq has a message that ends with "Can anyone | reproduce this?", and there are no followups. This makes for a weak | reference. There are also no other references listed for this CAN. | LeBlanc> - no follow-ups, no KB article, no fix | CHANGE> [Frech changed vote from REVIEWING to REJECT]  View
1696  CVE-2000-0118  Candidate  The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.  Proposed (20000208)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> Is this the same issue as BugTraq Mailing List, Wed, 9 Jun 1999 14:07:27 | -0700 "vulnerability in su/PAM in redhat" at | http://www.netspace.org/cgi-bin/wa?A2=ind9906b&L=bugtraq&F=&S=&P=5356 and | "Solaris 2.5 /bin/su [was: vulnerability in su/PAM in redhat]" at | http://www.netspace.org/cgi-bin/wa?A2=ind9906b&L=bugtraq&F=&S=&P=6051 | If so, then MODIFY XF:su-brute | Christey> BID:320 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=320 | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:su-brute(2278) | This issue involves more platforms than Red Hat. See BugTraq | Mailing List, Thu Jun 10 1999 12:13:06, "Solaris 2.5 /bin/su [was: | vulnerability in su/PAM in redhat]", | http://www.securityfocus.com/archive/1/14854 | Christey> It does look like this is the same issue as the other Bugtraq | post that explicitly mentions Red Hat and PAM. | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
1697  CVE-2000-0119  Candidate  The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.  Proposed (20000208)  ACCEPT(2) Cole, Wall | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Christey  Christey> ADDREF BID:956 | | A followup post on Feb 8 by Paul L Schmehl claims that this | would not work, because the anti-virus checkers would | activate if the user attempts to execute the program. | Frech> XF:win-trojan-detection-bypass | Much earlier possible reference at NTBugtraq Mailing List, Wed, 22 Dec 1999 | 20:37:43 -0800, "Bypass Virus Checking under 95/98/NT" at | http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9912&L=ntbugtraq&F=&S=&P=6030 | CHANGE> [Cole changed vote from REVIEWING to ACCEPT] | Christey> NTBUGTRAQ:19991222 Bypass Virus Checking under 95/98/NT | http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9912&L=ntbugtraq&F=&S=&P=6030  View

Page 378 of 20943, showing 5 records out of 104715 total, starting on record 1886, ending on 1890

Actions