CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2922  CVE-2001-0101  Candidate  Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.  Modified (20020222-01)  ACCEPT(4) Baker, Cole, Prosser, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Prosser> TURBO:TLSA2000024-1 | http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:fetchmail-authenticate-gssapi(7455)  View
1903  CVE-2000-0325  Candidate  The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.  Modified (20020222-01)  ACCEPT(5) Armstrong, Baker, Cole, Prosser, Wall | MODIFY(1) Frech | REJECT(1) LeBlanc | REVIEWING(1) Christey  LeBlanc> - same as CVE-1999-1011 | If I"m misunderstanding something here, please correct me. In fact, it has | the same bulletin as a reference. | Frech> XF:jet-vba-shell | Prosser> This entry is not the same as "now" CVE-1999-1011. That entry is "The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands." This one should be correct. | Christey> BUGTRAQ:19990525 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=bugtraq&m=92765973107637&w=2 | NTBUGTRAQ:19990526 Advisory: NT ODBC Remote Compromise | http://marc.theaimsgroup.com/?l=ntbugtraq&m=92781907215748&w=2 | Christey> The Microsoft advisory itself describes two separate | vulnerabilities, calling the TEXT I-ISAM problem | (CVE-2000-0323) a variant of the VBA Shell problem (this | CAN). In addition, CVE-2000-0323 does *not* appear in Jet | 4.0, while this one does. Since one problem appears in a | different version than the other, CD:SF-LOC suggests keeping | these candidates SPLIT. | | BID:548 | http://www.securityfocus.com/bid/548 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Need to clarify whether the Bugtraq/NTBugtraq posts are | really describing the same issue (those are BID:286).  View
1538  CVE-1999-1558  Candidate  Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.  Modified (20020218-01)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:openvms-loginout-unauth-access(7151)  View
1288  CVE-1999-1308  Candidate  Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.  Modified (20020218-01)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech  Frech> XF:hp-large-uid-gid(7594)  View
1547  CVE-1999-1567  Candidate  Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending any data.  Modified (20020218-01)  ACCEPT(2) Cole, Foat | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:testtrack-dos(1948)  View

Page 555 of 20943, showing 5 records out of 104715 total, starting on record 2771, ending on 2775

Actions