CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2606  CVE-2000-1037  Candidate  Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.  Proposed (20001129)  ACCEPT(2) Baker, Mell | NOOP(2) Cole, Wall    View
2487  CVE-2000-0918  Candidate  Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.  Proposed (20001129)  ACCEPT(2) Baker, Mell | NOOP(2) Cole, Wall | REVIEWING(1) Christey  Christey> May be a duplicate of CVE-2000-0373, but the ref"s in that CVE | are vague. I suspect this *isn"t* a duplicate because this is | a format string problem. | Baker> I think it is sufficiently different from 2000-0373.  View
2472  CVE-2000-0903  Candidate  Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.  Proposed (20001129)  ACCEPT(2) Baker, Mell | NOOP(3) Cole, Collins, Wall  Collins> Assigning CVE numbers for demo software is not appropriate | Baker> Was this a beta version in the demo disk? I don"t think it was. While we do have an exclusion for beta software, | software that is distributed as production software, just limited in scope, does not mean beta.. | The current version is 4, but it is still offered for free download from their website for use. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT] | Baker> SHould change vote from review to accept  View
572  CVE-1999-0590  Candidate  A system does not present an appropriate legal message or warning to a user who is accessing it.  Proposed (19990728)  ACCEPT(2) Baker, Northcutt | MODIFY(1) Christey | RECAST(1) Shostack  Christey> ADDREF CIAC:J-043 | URL:http://ciac.llnl.gov/ciac/bulletins/j-043.shtml | Also add "banner" to the description to facilitate search. | Baker> Should be in place where ever it is possible  View
507  CVE-1999-0510  Candidate  A router or firewall allows source routed packets from arbitrary hosts.  Proposed (19990726)  ACCEPT(2) Baker, Northcutt | MODIFY(1) Frech  Frech> XF:source-routing  View

Page 801 of 20943, showing 5 records out of 104715 total, starting on record 4001, ending on 4005

Actions