CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2401  CVE-2000-0832  Candidate  Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.  Modified (20010910-01)  ACCEPT(2) Baker, Collins | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Wall  Frech> XF:htgrep-cgi-view-files(5476) | Collins> http://www.iam.unibe.ch/~scg/Src/Doc/ | Christey> The change log for htgrep acknowledges the problem, but it | says that the qry tag is also affected. CD:SF-LOC says that | multiple problems of the same type in the same version should | be combined, so this candidate should get a "soft recast" | and qry should be added to the description.  View
2402  CVE-2000-0833  Candidate  Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.  Modified (20020222-01)  ACCEPT(5) Baker, Cole, Collins, Frech, Wall | NOOP(2) Armstrong, Magdych  Cole> HAS-INDEPENDENT-CONFIRMATION | CHANGE> [Wall changed vote from REVIEWING to ACCEPT]  View
2403  CVE-2000-0834  Entry  The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.        View
2404  CVE-2000-0835  Candidate  search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.  Modified (20100115)  MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Collins, Wall | REJECT(2) Baker, Magdych  Magdych> Unless the beta product is in very widespread use, or the product is in | "perpetual beta" (e.g. ICQ), I would prefer not to include beta software. | Christey> XF:sambar-search-view-folder | Frech> XF:sambar-search-view-folder(5247) | Baker> Unless we change our CD:EX-BETA, we should reject this entry. Perhaps we need to address the issue of Beta software again, but the previous discussion was pretty thorough and I believe the editorial board was unanimous in excluding normal beta software. | Christey> Fix typo: "paramater" | Christey> fix typo: "paramatar"  View
2405  CVE-2000-0836  Candidate  Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.  Proposed (20001018)  ACCEPT(2) Baker, Frech | NOOP(3) Armstrong, Cole, Magdych | REVIEWING(1) Wall    View

Page 481 of 20943, showing 5 records out of 104715 total, starting on record 2401, ending on 2405

Actions