CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1379 | CVE-1999-1399 | Candidate | spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:spaceware-hostname-command-execution(7194) | View |
1006 | CVE-1999-1026 | Candidate | aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:sun-aspppd-tmp-symlink(7173) | View |
1794 | CVE-2000-0216 | Candidate | Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list. | Proposed (20000322) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REJECT(3) Blake, LeBlanc, Levy | REVIEWING(1) Wall | Blake> This is a configuration issue. Should the fact that NT can be configured | to accept a blank Admin password have a CVE entry? | LeBlanc> This is documented as bad practice - if you have a wide distribution | mailing list, you should only allow certain users to send mail to it. | I don"t think we want to start listing all possible admin errors as | vulnerabilities. | Frech> XF:microsoft-mail-client-dos(4893) | Levy> I agree with all the above comments. Furthermore the delivery status | notification RFC makes it clear that mailing list software should | strip messages from DSN headers. I assume Microsoft"s products are | using the DSN standard and not something else. | View |
1108 | CVE-1999-1128 | Candidate | Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Christey, Foat | Frech> XF:http-ie-exec(462) | Christey> DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html | ADDREF MISC:http://focus.silversand.net/vulner/allbug/ie3.html | View |
4714 | CVE-2002-0322 | Candidate | Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing. | Proposed (20020502) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Cox, Foat | REVIEWING(1) Wall | Frech> XF:yahooim-plaintext-password(5943) | View |
Page 646 of 20943, showing 5 records out of 104715 total, starting on record 3226, ending on 3230