CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
355 | CVE-1999-0356 | Candidate | ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book. | Proposed (19990721) | ACCEPT(2) Baker, Frech | NOOP(2) Northcutt, Wall | RECAST(1) Ozancin | View | |
611 | CVE-1999-0629 | Candidate | The ident/identd service is running. | Proposed (19990721) | ACCEPT(2) Baker, Ozancin | MODIFY(1) Frech | NOOP(2) Christey, Wall | REJECT(1) Northcutt | Frech> possibly XF:identd? | Christey> XF:ident-users(318) ? | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:identd-vuln(61) | XF:ident-users(318) | View |
474 | CVE-1999-0476 | Candidate | A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user. | Proposed (19990721) | ACCEPT(3) Baker, Frech, Ozancin | NOOP(3) LeBlanc, Northcutt, Wall | View | |
497 | CVE-1999-0499 | Candidate | NETBIOS share information may be published through SNMP registry keys in NT. | Proposed (19990721) | ACCEPT(5) Baker, Northcutt, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc | Frech> Change wording to "Windows NT." | XF:snmp-netbios | LeBlanc> Share info can be obtained via SNMP queries, but I question | whether this is a vulnerability. The system can be configured not to do | this, and one may argue that SNMP itself is an insecure configuration. | Furthermore, the share information isn"t published via registry keys - | the description could refer to more than one actual issue. SNMP is meant | to allow people to obtain information about systems. I"m willing to | discuss this with the rest of the board. | View |
513 | CVE-1999-0516 | Candidate | An SNMP community name is guessable. | Proposed (19990714) | ACCEPT(4) Baker, Meunier, Northcutt, Shostack | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:snmp-get-guess | XF:snmp-set-guess | XF:sol-hidden-commstr | XF:hpov-hidden-snmp-comm | Christey> This candidate is affected by the CD:CF-PASS content decision, | which determines the appropriate level of abstraction to | use for password problems. CD:CF-PASS needs to be accepted | by the Editorial Board before this candidate can be | converted into a CVE entry; the final version of CD:CF-PASS | may require using a different LOA than this candidate is | currently using. | View |
Page 419 of 20943, showing 5 records out of 104715 total, starting on record 2091, ending on 2095