CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
842 | CVE-1999-0862 | Candidate | Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file. | Proposed (19991208) | ACCEPT(3) Armstrong, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Prosser | Frech> XF:postgresql-insecure-perms | View |
843 | CVE-1999-0863 | Candidate | Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI. | Proposed (19991208) | ACCEPT(4) Armstrong, Cole, Prosser, Stracener | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Christey | Frech> XF:freebsd-seyon-bo | Christey> ADDREF? CALDERA:CSSA-1999-037.0 | Christey> May be multiple bugs here, or a single library problem. | CD:SF-LOC needs to be resolved before determining if this | candidate should be SPLIT. Also see CVE-1999-0821. | View |
890 | CVE-1999-0910 | Candidate | Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user. | Proposed (19991208) | ACCEPT(4) Baker, Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(1) Cole | Frech> XF:siteserver-cis-cookie-cache | Cole> Whether cookies are a vulnerbality is a debate for another time, the | question here is whether the | expiration feature is a vulnerability and I do not think it is | because the underlying concerns for this | are present even without this feature. The expiration feature does | not add any new vulenrabilities | that are not already present with cookies. | Stracener> Add Ref: MSKB Q238647 | View |
651 | CVE-1999-0670 | Candidate | Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. | Proposed (19991208) | ACCEPT(3) Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(2) Baker, Cole | Frech> XF:ie-eyedog-bo | Cole> Based on the references and information listed this is the same as | CVE-1999-0669 | Stracener> Add Ref: MSKB Q240308 | Baker> Duplicate | View |
717 | CVE-1999-0737 | Candidate | The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | Proposed (19991208) | ACCEPT(4) Ozancin, Prosser, Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | Frech> XF:iis-samples-viewcode | Cole> I would combine this with the previous. | Prosser> (modify) | See comments in 0736 above | Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html | for additional details. | Christey> Mark Burnett"s article is at: | MISC:http://www.securityfocus.com/infocus/1317 | View |
Page 394 of 20943, showing 5 records out of 104715 total, starting on record 1966, ending on 1970