CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1663 | CVE-2000-0085 | Candidate | Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag. | Proposed (20000125) | ACCEPT(1) Baker | MODIFY(1) Frech | Frech> XF:hotmail-java-execute | View |
1664 | CVE-2000-0086 | Candidate | Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing. | Proposed (20000125) | ACCEPT(2) Baker, Williams | MODIFY(1) Frech | Frech> XF:timbuktu-password-cleartext | View |
1586 | CVE-2000-0008 | Candidate | FTPPro allows local users to read sensitive information, which is stored in plain text. | Proposed (20000111) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy | Frech> XF:ftppro-plaintext-information | Christey> ADDREF BID:1790 | ADDREF URL:http://www.securityfocus.com/bid/1790 | View |
1594 | CVE-2000-0016 | Candidate | Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username. | Proposed (20000111) | ACCEPT(4) Armstrong, Baker, Levy, Stracener | MODIFY(1) Frech | Frech> XF:iams-pop3-command-dos | View |
1595 | CVE-2000-0017 | Candidate | Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter. | Proposed (20000111) | NOOP(4) Armstrong, Baker, Christey, Stracener | REJECT(2) Frech, Levy | Christey> It"s not certain whether this is exploitable or not. An | expert (the linuxconf author?) wasn"t able to duplicate the | bug - see http://lwn.net/1999/1223/a/linuxconfresponse.html | | The original posting with example exploit was | http://marc.theaimsgroup.com/?l=bugtraq&m=94580196627059&w=2 | | However - GIAC and the Security Focus incidents list have | consistently reported that scans are taking place for | linuxconf, so do the hackers know more than we do? | Frech> Unless vendor or other confirmation occurs, there has been no corroboration | of this issue in public forums. | CHANGE> [Armstrong changed vote from ACCEPT to NOOP] | View |
Page 384 of 20943, showing 5 records out of 104715 total, starting on record 1916, ending on 1920