CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2103  CVE-2000-0526  Candidate  mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20000712)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> ADDREF XF:mailstudio-view-files | Frech> XF:mailstudio-view-files(4737)  View
2104  CVE-2000-0527  Candidate  userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.  Proposed (20000712)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> Modify description - explicitly mention %0a string; other | metachar"s are filtered | Frech> XF:mailstudio-cgi-input-vaildation(4739)  View
2148  CVE-2000-0572  Candidate  The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges.  Proposed (20000719)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Cole, LeBlanc, Magdych, Wall  Frech> XF;razor-weak-encryption(4875) | CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
2140  CVE-2000-0564  Candidate  The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter.  Proposed (20000712)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(5) Christey, Cole, LeBlanc, Ozancin, Wall  Christey> ADDREF BID:1463 | URL:http://www.securityfocus.com/bid/1463 | Frech> XF:icq-webfront-guestbook-dos(4574)  View
230  CVE-1999-0231  Candidate  Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.  Modified (19991207-01)  ACCEPT(2) Baker, Levy | NOOP(3) Christey, Landfield, Northcutt | RECAST(1) Frech | REVIEWING(1) Ozancin  Frech> XF:slmail-vrfyexpn-overflow (for Slmail v3.2 and below) | XF:smtp-vrfy-bo (many mail packages) | Northcutt> (There is no way I will have access to these systems) | Christey> Some sources report that VRFY and EXPN are both affected.  View

Page 799 of 20943, showing 5 records out of 104715 total, starting on record 3991, ending on 3995

Actions