CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3081  CVE-2001-0260  Entry  Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.        View
3082  CVE-2001-0261  Candidate  Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.  Proposed (20010404)  ACCEPT(3) Baker, Bishop, Frech | NOOP(3) Christey, Cole, Ziese | REJECT(1) LeBlanc | REVIEWING(1) Wall  Bishop> Sounds like Microsoft just confirmed it! | Christey> The description should make the point that the original files | are in plaintext. | LeBlanc> The preconditions needed to obtain the clear-text backup file | are that the user must be able to read the raw disk. Only administrators | or those with physical access can read the raw disk. An admin could | alter the operating system such that anything a user did would be | available, even EFS information (since the admin can cause processes to | run as any user who is logged on currently). Thus even if this issue | were not present, the same set of preconditions would lead to access to | the same information. In the case of physical access, scrubbing the disk | should be viewed only as raising the bar - information can be recovered | even from overwritten sectors. Additionally, coverage of a file might | not be complete - in the case where a file is truncated, then encrypted, | there could be sectors with file information that the operating system | would have no knowledge of at the time the encryption occurred, and | there is no practical way to wipe these. Considering all the realities | of the situation, the only real-world solution is to create files you"d | like encrypted in a directory marked for encryption. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT]  View
3083  CVE-2001-0262  Candidate  Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.  Proposed (20010524)  ACCEPT(3) Baker, Cole, Williams | MODIFY(1) Frech | NOOP(4) Christey, Renaud, Wall, Ziese  Frech> XF:netscape-smartdownload-sdph20-bo(6403) | Christey> BUGTRAQ:20010418 Netscape SmartDownload 1.3 Buffer Overflow Vulnerability | URL:http://www.securityfocus.com/archive/1/177589 | Add sdph20.dll as affected component in description, as | indicated by above post. | Christey> Consider adding BID:2615  View
3084  CVE-2001-0263  Candidate  Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.  Modified (20010222-02)  ACCEPT(3) Baker, Cole, Renaud | MODIFY(1) Frech | NOOP(3) Oliver, Wall, Ziese  Frech> XF:bpftp-obtain-credentials(6330)  View
3085  CVE-2001-0264  Candidate  Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.  Proposed (20010524)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Oliver, Wall | REVIEWING(1) Ziese  Frech> XF:bpftp-obtain-credentials(6330)  View

Page 617 of 20943, showing 5 records out of 104715 total, starting on record 3081, ending on 3085

Actions