CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2267  CVE-2000-0691  Candidate  The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.  Proposed (20000921)  ACCEPT(1) Levy | MODIFY(2) Cox, Frech | NOOP(3) Christey, Cole, Wall  Frech> XF:mgetty-faxrunq-symlink | Christey> ADDREF XF:mgetty-faxrunq-symlink | ADDREF URL:http://xforce.iss.net/static/5159.php | ADDREF REDHAT:RHSA-2000:059-02 | ADDREF BUGTRAQ:20000830 Conectiva Linux Security Announcement - mgetty | ADDREF MANDRAKE:MDKSA-2000:042 | Christey> ADDREF REDHAT:RHSA-2000:059-02 | Christey> ADDREF FREEBSD:FreeBSD-SA-00:71 | ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:71.mgetty.asc | Frech> XF:mgetty-faxrunq-symlink(5159) | Cox> ADDREF REDHAT:RHSA-2000:059  View
2070  CVE-2000-0492  Candidate  PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords.  Proposed (20000712)  ACCEPT(1) Levy | MODIFY(2) Frech, Ozancin | NOOP(2) LeBlanc, Wall  Ozancin> change "attacker who can read the password" to "attacker to decrypt and read | the password" | Frech> XF:passwd-weak-encryption(4596)  View
730  CVE-1999-0750  Candidate  Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user"s Hotmail account.  Proposed (19991222)  ACCEPT(1) Levy | MODIFY(2) Frech, Stracener | NOOP(1) Baker  Stracener> Many sites are vulnerable to this problem. I recommend removing the | explicit references to Hotmail and making the description more generic. | Suggest: Javascript can be injected using the STYLE tag in an HTML | formatted e-mail, allowing remote attackers to execute commands on user | accounts. | Frech> XF:hotmail-html-style-embed  View
2080  CVE-2000-0503  Candidate  The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.  Proposed (20000712)  ACCEPT(1) Levy | MODIFY(2) Frech, Wall | NOOP(2) LeBlanc, Ozancin | REVIEWING(1) Christey  Wall> This affects more than IE 5.01. See http://www.securityfocus.com/bid/1311 for | all versions of IE that this affects. Works on Windows 98, IE 5.01 and IE 5.5. | LeBlanc> If this is the one I was discussing offline with Steve, ACCEPT | Frech> XF:ie-cross-frame(4610) | Christey> Make sure this is the one I was discussing offline with David :-) | Frech> CVE-2000-0503 was reassigned to ie-frame-domain-file-access(5504) from | ie-cross-frame(4610), which was obsoleted and redirected to this | issue. Since these are the same issues but just described differently, | CVE-2000-0503 appears to be a dupe of CVE-2000-0768.  View
2324  CVE-2000-0748  Candidate  OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.  Proposed (20000921)  ACCEPT(1) Levy | NOOP(4) Baker, Cole, Wall, Williams    View

Page 740 of 20943, showing 5 records out of 104715 total, starting on record 3696, ending on 3700

Actions