CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2267 | CVE-2000-0691 | Candidate | The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file. | Proposed (20000921) | ACCEPT(1) Levy | MODIFY(2) Cox, Frech | NOOP(3) Christey, Cole, Wall | Frech> XF:mgetty-faxrunq-symlink | Christey> ADDREF XF:mgetty-faxrunq-symlink | ADDREF URL:http://xforce.iss.net/static/5159.php | ADDREF REDHAT:RHSA-2000:059-02 | ADDREF BUGTRAQ:20000830 Conectiva Linux Security Announcement - mgetty | ADDREF MANDRAKE:MDKSA-2000:042 | Christey> ADDREF REDHAT:RHSA-2000:059-02 | Christey> ADDREF FREEBSD:FreeBSD-SA-00:71 | ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:71.mgetty.asc | Frech> XF:mgetty-faxrunq-symlink(5159) | Cox> ADDREF REDHAT:RHSA-2000:059 | View |
2070 | CVE-2000-0492 | Candidate | PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(2) Frech, Ozancin | NOOP(2) LeBlanc, Wall | Ozancin> change "attacker who can read the password" to "attacker to decrypt and read | the password" | Frech> XF:passwd-weak-encryption(4596) | View |
730 | CVE-1999-0750 | Candidate | Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user"s Hotmail account. | Proposed (19991222) | ACCEPT(1) Levy | MODIFY(2) Frech, Stracener | NOOP(1) Baker | Stracener> Many sites are vulnerable to this problem. I recommend removing the | explicit references to Hotmail and making the description more generic. | Suggest: Javascript can be injected using the STYLE tag in an HTML | formatted e-mail, allowing remote attackers to execute commands on user | accounts. | Frech> XF:hotmail-html-style-embed | View |
2080 | CVE-2000-0503 | Candidate | The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event. | Proposed (20000712) | ACCEPT(1) Levy | MODIFY(2) Frech, Wall | NOOP(2) LeBlanc, Ozancin | REVIEWING(1) Christey | Wall> This affects more than IE 5.01. See http://www.securityfocus.com/bid/1311 for | all versions of IE that this affects. Works on Windows 98, IE 5.01 and IE 5.5. | LeBlanc> If this is the one I was discussing offline with Steve, ACCEPT | Frech> XF:ie-cross-frame(4610) | Christey> Make sure this is the one I was discussing offline with David :-) | Frech> CVE-2000-0503 was reassigned to ie-frame-domain-file-access(5504) from | ie-cross-frame(4610), which was obsoleted and redirected to this | issue. Since these are the same issues but just described differently, | CVE-2000-0503 appears to be a dupe of CVE-2000-0768. | View |
2324 | CVE-2000-0748 | Candidate | OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse. | Proposed (20000921) | ACCEPT(1) Levy | NOOP(4) Baker, Cole, Wall, Williams | View |
Page 740 of 20943, showing 5 records out of 104715 total, starting on record 3696, ending on 3700