CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6876  CVE-2003-0047  Candidate  SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.  Modified (20071121)  ACCEPT(2) Baker, Stracener | NOOP(4) Cole, Cox, Green, Wall  Green> MULTIPLE VENDORS INVOLVED | Stracener> I"m going to go with this because at least two of the affected vendors acknowledged a fix in the original advisory.  View
633  CVE-1999-0651  Candidate  The rsh/rlogin service is running.  Proposed (19990804)  ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Christey | REJECT(1) Northcutt  Christey> aka "shell" on UNIX systems (at least Solaris) in the | /etc/inetd.conf file. | Frech> associated to: | XF:nt-rlogin(92) | XF:rsh-svc(114) | XF:rshd(2995)  View
2714  CVE-2000-1147  Candidate  Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag.  Modified (20010116-01)  ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Cole | RECAST(1) LeBlanc | REVIEWING(1) Christey  Frech> XF:iis-isapi-asp-bo(5510) | Christey> Consult Microsoft on this one. | LeBlanc> This one was already fixed in several hotfixes when it was | found. I"m not sure what the content decision is on this. It is a valid | problem, but it was already fixed when announced. I will go along with | an accept vote once it is modified to show fixes.  View
2660  CVE-2000-1093  Candidate  Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.  Modified (20010417-01)  ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Christey  Frech> XF:aim-remote-bo(5732) | Christey> CD:SF-LOC as currently written suggests merging this with | CVE-2000-1094, since both describe buffer overflows in the | same software version. | Christey> Consider adding BID:2118  View
577  CVE-1999-0595  Candidate  A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.  Proposed (19990728)  ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Northcutt  Frech> XF:nt-clearpage(216) | XF:reg-pagefile-clearing(2551)  View

Page 807 of 20943, showing 5 records out of 104715 total, starting on record 4031, ending on 4035

Actions