CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1597 | CVE-2000-0019 | Candidate | IMail POP3 daemon uses weak encryption, which allows local users to read files. | Proposed (20000111) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Christey | Frech> XF:imail-passwords | Levy> BID 880 | Christey> BUGTRAQ:19990304 IMAIL password recovery is trivial. | http://www.securityfocus.com/archive/1/12750 | Christey> Add version numbers (5.0 through 5.08) | View |
1613 | CVE-2000-0035 | Candidate | resend command in Majordomo allows local users to gain privileges via shell metacharacters. | Proposed (20000111) | ACCEPT(3) Baker, Levy, Stracener | MODIFY(2) Cox, Frech | NOOP(1) Armstrong | REVIEWING(1) Christey | Frech> XF:majordomo-local-resend | Christey> The Bugtraq thread indicates that this problem may be | due to misconfiguration, and may extend beyond just the | resend command. | CHANGE> [Armstrong changed vote from REVIEWING to NOOP] | Christey> Include "wrapper" to facilitate search and matching? (but | double-check CVE-2000-0037). | Add "1.94.4 and earlier" as the affected version number. | ADDREF AUSCERT:AA-2000.01 | ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.01 | Cox> ADDREF REDHAT:RHSA-2000:005 | View |
1616 | CVE-2000-0038 | Candidate | glFtpD includes a default glftpd user account with a default password and a UID of 0. | Proposed (20000111) | ACCEPT(2) Armstrong, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Baker | Frech> XF:glftpd-default-account | Levy> BID 881 | View |
775 | CVE-1999-0795 | Candidate | The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches. | Proposed (19991222) | ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(1) Ozancin | Frech> XF:sun-nisplus | View |
778 | CVE-1999-0798 | Candidate | Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type. | Proposed (19991222) | ACCEPT(3) Baker, Ozancin, Stracener | MODIFY(1) Frech | NOOP(1) Christey | Christey> Is CVE-1999-0389 a duplicate of CVE-1999-0798? CVE-1999-0389 | has January 1999 dates associated with it, while CVE-1999-0798 | was reported in late December. | | http://marc.theaimsgroup.com/?l=bugtraq&m=91278867118128&w=2 | | SCO appears to have acknowledged this as well: | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.01a | | The poster also claims that OpenBSD fixed this as well. | Frech> XF:bootp-remote-bo | Christey> Further analysis indicates that this is a duplicate of CVE-1999-0799 | CHANGE> [Christey changed vote from REJECT to NOOP] | Christey> What was I thinking? Brian Caswell pointed out that this is | *not* the same bug as CVE-1999-0799. As reported in the | 1998 Bugtraq post, the bug is in bootpd.c, and is related | to providing an htype value that is used as an index | into an array, and exceeds the intended boundaries of that | array. | View |
Page 385 of 20943, showing 5 records out of 104715 total, starting on record 1921, ending on 1925