CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2226 | CVE-2000-0650 | Entry | The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse. | View | |||
2227 | CVE-2000-0651 | Entry | The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim"s machine. | View | |||
2228 | CVE-2000-0652 | Entry | IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string. | View | |||
2229 | CVE-2000-0653 | Candidate | Microsoft Outlook Express allows remote attackers to monitor a user"s email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability. | Proposed (20000803) | ACCEPT(3) Cole, Levy, Wall | NOOP(1) LeBlanc | REJECT(1) Frech | REVIEWING(1) Christey | Frech> Is this a duplicate of CVE-2000-0105? I can find no differentiating evidence | to show that this issue is unique. | Christey> I need to look through my email logs to recall whether I | resolved this potential duplicate with Microsoft people. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | View |
2230 | CVE-2000-0654 | Entry | Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. | View |
Page 446 of 20943, showing 5 records out of 104715 total, starting on record 2226, ending on 2230