CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1976  CVE-2000-0398  Entry  Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.        View
1977  CVE-2000-0399  Entry  Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name.        View
1978  CVE-2000-0400  Candidate  The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user"s system by encoding it within an email message or news post.  Proposed (20000615)  ACCEPT(4) Frech, Levy, Ozancin, Wall | NOOP(2) Cole, Stracener | REJECT(1) Christey | REVIEWING(1) LeBlanc  LeBlanc> COMMENT - this definately will not work if the user has applied the security | patch. I don"t know whether this repros right now, and have sent a query to | find out. | Christey> Is this now documented in MS:MS00-042? | LeBlanc> the problem isn"t in the Active Movie control. What was | observed was a symptom of another problem that got fixed in | some bulletin or another - I don"t remember. | Christey> According to Scott Culp, this existed because | the patch for the Cache Bypass vulnerability (MS:MS00-046, | CVE-2000-0621) was not applied, so this should be REJECTed | as a duplicate of CVE-2000-0621.  View
1979  CVE-2000-0401  Candidate  Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.  Proposed (20000615)  ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:pdgsoft-changepw-bo | XF:pdgsoft-redirect-bo  View
1980  CVE-2000-0402  Entry  The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.        View

Page 396 of 20943, showing 5 records out of 104715 total, starting on record 1976, ending on 1980

Actions