CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2671  CVE-2000-1104  Candidate  Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.  Proposed (20001219)  ACCEPT(3) Baker, Cole, Wall | MODIFY(1) Frech  Frech> XF:iis-cross-site-scripting(5156)  View
2672  CVE-2000-1105  Candidate  The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.  Proposed (20001219)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | REVIEWING(2) Christey, Wall  Frech> XF:win2k-index-service-ixsso(5502) | Christey> ADDREF MS:MS00-098 | ADDREF XF:win2k-index-service-activex | URL:http://xforce.iss.net/static/5800.php | Add "aka the "Indexing Service File Enumeration" vulnerability" | to the description. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> DUPE CVE-2001-0245? Need to check w/Microsoft.  View
2673  CVE-2000-1106  Entry  Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.        View
2674  CVE-2000-1107  Entry  in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.        View
2675  CVE-2000-1108  Entry  cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.        View

Page 535 of 20943, showing 5 records out of 104715 total, starting on record 2671, ending on 2675

Actions