CVE List

Id CVE No. Status Description Phase Votes Comments Actions
564  CVE-1999-0582  Candidate  A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.  Proposed (19990721)  ACCEPT(3) Ozancin, Shostack, Wall | MODIFY(2) Baker, Frech | REJECT(1) Northcutt  Northcutt> The definition is? | Baker> Maybe a rewording of this one too. I think most people would agree on | some "minimum" policies like 3-5 bad attempts lockout for an hour or | until the administrator unlocks the account. | Suggested rewrite - | A Windows NT account policy does not enforce reasonable minimum | security-critical settings for lockouts, e.g. lockout duration, | lockout after bad logon attempts, etc. | Ozancin> with reservations | What is appropriate? | Frech> XF:nt-thres-lockout | XF:nt-lock-duration | XF:nt-lock-window | XF:nt-perm-lockout | XF:lockout-disabled  View
567  CVE-1999-0585  Candidate  A Windows NT administrator account has the default name of Administrator.  Proposed (19990721)  ACCEPT(1) Ozancin | MODIFY(1) Frech | REJECT(3) Baker, Northcutt, Shostack | REVIEWING(1) Wall  Wall> Some sources say this is not a vulnerability, but a warning. It just | slows down the search for the admin account (SID = 500) which can | always be found. | Northcutt> I change this on all NT systems I am responsible for, but is | root a vulnerability? | Baker> There are ways to identify the administrator account anyway, so this | is only a minor delay to someone that is knowledgeable. This, in and | of itself, doesn"t really strike me as a vulnerability, anymore than | the root account on a Unix box. | Shostack> (there is no way to hide the account name today) | Frech> XF:nt-adminexists  View
595  CVE-1999-0613  Candidate  The rpc.sprayd service is running.  Proposed (19990721)  ACCEPT(2) Baker, Ozancin | MODIFY(1) Frech | NOOP(1) Wall | REJECT(1) Northcutt  Frech> XF:sprayd  View
351  CVE-1999-0352  Candidate  ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.  Proposed (19990721)  ACCEPT(2) Baker, Frech | NOOP(2) Northcutt, Wall | RECAST(1) Ozancin  Ozancin> Can we combine this with CVE-1999-0356 - ControlIT(tm) 4.5 and earlier uses | weak encryption.  View
607  CVE-1999-0625  Candidate  The rpc.rquotad service is running.  Proposed (19990721)  ACCEPT(3) Baker, Northcutt, Ozancin | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:rquotad  View

Page 418 of 20943, showing 5 records out of 104715 total, starting on record 2086, ending on 2090

Actions