CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
567 | CVE-1999-0585 | Candidate | A Windows NT administrator account has the default name of Administrator. | Proposed (19990721) | ACCEPT(1) Ozancin | MODIFY(1) Frech | REJECT(3) Baker, Northcutt, Shostack | REVIEWING(1) Wall | Wall> Some sources say this is not a vulnerability, but a warning. It just | slows down the search for the admin account (SID = 500) which can | always be found. | Northcutt> I change this on all NT systems I am responsible for, but is | root a vulnerability? | Baker> There are ways to identify the administrator account anyway, so this | is only a minor delay to someone that is knowledgeable. This, in and | of itself, doesn"t really strike me as a vulnerability, anymore than | the root account on a Unix box. | Shostack> (there is no way to hide the account name today) | Frech> XF:nt-adminexists | View |
1303 | CVE-1999-1323 | Candidate | Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE. | Proposed (20010912) | ACCEPT(1) Prosser | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:nav-admin-password(7543) | Prosser> This has been since corrected in later releases. | View |
1923 | CVE-2000-0345 | Candidate | The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command. | Proposed (20000518) | ACCEPT(1) Prosser | MODIFY(1) Frech | NOOP(5) Armstrong, Baker, Cole, Levy, Wall | REJECT(1) Balinsky | Levy> Arguably this is not a vulnerability. Cisco replying saying this | is standard behaviour that was simply not well documented. They have | no plans to change it and will simply document it better. | Frech> XF:cisco-online-help | Balinsky> As noted in a bugtraq posting by Lisa Napier from Cisco"s Product Security Incident Response Team, this is a poorly documented feature. This is intended behavior, and does not represent a vulnerability in Cisco"s opinion. | http://www.securityfocus.com/frames/?content=/templates/archive.pike?list=1&mid=59434 | Prosser> Although Lisa Napier did say this issue was "functioning as designed", it was not intended to allow unprivileged access. Lisa did indicate that Cisco would be updating instructions on configuration to ensure proper user privileges. So, this should be considered IMHO an "exposure" vice a vulnerability, but security-related none the less. | http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000502222246.28423.qmail@securityfocus.com | | http://www.securityfocus.com/bid/1161 | View |
4877 | CVE-2002-0485 | Candidate | Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients. | Modified (20040811) | ACCEPT(1) Prosser | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nav-case-bypass-protection(9860) | Prosser> This issues was a continuation of an earlier reported issue | with non-RFC compliant MIME headers. The discover was testing a | non-updated version of NAV 2002 which was vulnerable to this and other | non-RFC compliant configurations. Updated and current releases are not | vulnerable to this problem | | http://securityresponse.symantec.com/avcenter/security/Content/2002.04.03.html | is the posted response to this issue. | View |
3301 | CVE-2001-0484 | Candidate | Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages. | Modified (20020223-01) | ACCEPT(1) Renaud | MODIFY(2) Baker, Frech | NOOP(6) Balinsky, Cole, Oliver, Wall, Williams, Ziese | REVIEWING(1) Christey | Williams> there was an issue with admin passwd storage for Tektronix Phaser 360, 740, 780, 840 | Frech> XF:tektronix-phaserlink-webserver-backdoor(6482) | Baker> 750DP and 930 printers should be added | http://www.securityfocus.com/archive/1/181007 | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> CVE-1999-1508 covered the older versions discussed | by Ken Williams. These may be duplicates. | This one is BID:2659 | http://www.securityfocus.com/bid/2659 | View |
Page 744 of 20943, showing 5 records out of 104715 total, starting on record 3716, ending on 3720