CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1991  CVE-2000-0413  Candidate  The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.  Proposed (20000615)  ACCEPT(7) Baker, Cole, Frech, LeBlanc, Levy, Ozancin, Stracener | MODIFY(1) Prosser | NOOP(1) Christey  Prosser> additional source Security BugWare | http://161.53.42.3/~crv/security/bugs/NT/fpse10.html comments on page re: | "MS soon to be released service release OSR 1.2 with needed changes." | I haven"t located anything on MS site yet. Anyone help? | Christey> BID:1433 may also refer to this issue. | Christey> [note to self: review comments by Mark Burnett] | Christey> CHANGEREF XF:iis-shtml-reveal-path XF:frontpage-ext-shtml-path(4439) | LeBlanc> Fixes are up on site now - have been for a while.  View
1992  CVE-2000-0414  Entry  Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.        View
1993  CVE-2000-0415  Candidate  Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.  Proposed (20000615)  ACCEPT(3) Levy, Ozancin, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cole, Stracener | REJECT(1) LeBlanc  LeBlanc> The poster re-discovered a vulnerability we patched two years | ago, in | http://www.microsoft.com/technet/security/bulletin/ms98-008.asp | Microsoft posted a response to BugTraq when this one went | public, and reminded them that we"d already patched it. | | BTW, I think we want to try and pay attention to follow-ups to | these threads in order to minimize noise in the process. | Christey> Based on David"s comments, this is covered by CVE-1999-0002. | However, that candidate may wind up being SPLIT, so I will | keep this one around for the moment. | | With respect to watching followups, we are relying quite | a bit on other data feeds instead of doing our own reviews | of all the different data sources. The data feeds may report | these problems as new before corrections are posted. | Followups do often lend additional information to the | candidates, and as is the case with this one, we will | often catch the discrepancy before the candidate becomes an | official entry, whether by MITRE"s own analysis or by that | of other Board members. | Frech> XF:outlook-image-long-filename  View
1994  CVE-2000-0416  Entry  NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail"s web configuration server.        View
1995  CVE-2000-0417  Entry  The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password.        View

Page 399 of 20943, showing 5 records out of 104715 total, starting on record 1991, ending on 1995

Actions