CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2136 | CVE-2000-0559 | Candidate | eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | Frech> XF:etrust-weak-password-encryption(5051) | View |
2137 | CVE-2000-0561 | Entry | Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request. | View | |||
2138 | CVE-2000-0562 | Candidate | BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower. | Proposed (20000712) | ACCEPT(3) Armstrong, Cole, Levy | MODIFY(2) Baker, Frech | NOOP(1) Ozancin | REVIEWING(1) Christey | Levy> What do others think? Should this be a vuln? I can see the argument | that some features are simply not available unless you use the maximum | security settings. | Christey> At the very least, this needs to be modified to state that | this problem/concern applies to high ports in general, not | just Back orifice. | | The Bugtraq poster claims that BlackICE "shuts down" the port, | but only *after* some initial traffic "leaks" out. This may | be by design, but it does mean that there is a small window | of opportunity in which BlackICE may not work "as | advertised," even at lower security settings. | Christey> XF:blackice-security-level-nervous | BID:1389 | Frech> XF:blackice-security-level-nervous(4777) | CHANGE> [Levy changed vote from REVIEWING to ACCEPT] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Baker> I accept it more as a security exposure, than a real vulnerability. | It performs just as any other "firewall" or IDS product can be configured to | allow traffic without notifying the user. You can adjust settings on | any product that allow traffic that other people or organizations would | find unacceptable. So, as long as it is reflected that this is more of | a configuration that allows such traffic as opposed to a defective | or improperly functioning software issue, I don"t have a problem with | it. | View |
2139 | CVE-2000-0563 | Candidate | The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) Christey, Wall | REVIEWING(1) LeBlanc | Christey> Confirmed by Scott Culp, but this only applies to | outdated/unsupported versions of the JVM. | Frech> XF:macos-java-security-ignored(5052) | Christey> Consult with Microsoft to ensure that this is fixed by | MS:MS00-059. If so, then this might not just be in MacOS. | View |
2140 | CVE-2000-0564 | Candidate | The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter. | Proposed (20000712) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(5) Christey, Cole, LeBlanc, Ozancin, Wall | Christey> ADDREF BID:1463 | URL:http://www.securityfocus.com/bid/1463 | Frech> XF:icq-webfront-guestbook-dos(4574) | View |
Page 428 of 20943, showing 5 records out of 104715 total, starting on record 2136, ending on 2140