CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1976 | CVE-2000-0398 | Entry | Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request. | View | |||
1977 | CVE-2000-0399 | Entry | Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name. | View | |||
1978 | CVE-2000-0400 | Candidate | The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user"s system by encoding it within an email message or news post. | Proposed (20000615) | ACCEPT(4) Frech, Levy, Ozancin, Wall | NOOP(2) Cole, Stracener | REJECT(1) Christey | REVIEWING(1) LeBlanc | LeBlanc> COMMENT - this definately will not work if the user has applied the security | patch. I don"t know whether this repros right now, and have sent a query to | find out. | Christey> Is this now documented in MS:MS00-042? | LeBlanc> the problem isn"t in the Active Movie control. What was | observed was a symptom of another problem that got fixed in | some bulletin or another - I don"t remember. | Christey> According to Scott Culp, this existed because | the patch for the Cache Bypass vulnerability (MS:MS00-046, | CVE-2000-0621) was not applied, so this should be REJECTed | as a duplicate of CVE-2000-0621. | View |
1979 | CVE-2000-0401 | Candidate | Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string. | Proposed (20000615) | ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:pdgsoft-changepw-bo | XF:pdgsoft-redirect-bo | View |
1980 | CVE-2000-0402 | Entry | The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability. | View |
Page 396 of 20943, showing 5 records out of 104715 total, starting on record 1976, ending on 1980