CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2103 | CVE-2000-0526 | Candidate | mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Proposed (20000712) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall | Christey> ADDREF XF:mailstudio-view-files | Frech> XF:mailstudio-view-files(4737) | View |
2104 | CVE-2000-0527 | Candidate | userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters. | Proposed (20000712) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall | Christey> Modify description - explicitly mention %0a string; other | metachar"s are filtered | Frech> XF:mailstudio-cgi-input-vaildation(4739) | View |
2148 | CVE-2000-0572 | Candidate | The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges. | Proposed (20000719) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Cole, LeBlanc, Magdych, Wall | Frech> XF;razor-weak-encryption(4875) | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | View |
2140 | CVE-2000-0564 | Candidate | The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter. | Proposed (20000712) | ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(5) Christey, Cole, LeBlanc, Ozancin, Wall | Christey> ADDREF BID:1463 | URL:http://www.securityfocus.com/bid/1463 | Frech> XF:icq-webfront-guestbook-dos(4574) | View |
230 | CVE-1999-0231 | Candidate | Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access. | Modified (19991207-01) | ACCEPT(2) Baker, Levy | NOOP(3) Christey, Landfield, Northcutt | RECAST(1) Frech | REVIEWING(1) Ozancin | Frech> XF:slmail-vrfyexpn-overflow (for Slmail v3.2 and below) | XF:smtp-vrfy-bo (many mail packages) | Northcutt> (There is no way I will have access to these systems) | Christey> Some sources report that VRFY and EXPN are both affected. | View |
Page 799 of 20943, showing 5 records out of 104715 total, starting on record 3991, ending on 3995