CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
6876 | CVE-2003-0047 | Candidate | SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials. | Modified (20071121) | ACCEPT(2) Baker, Stracener | NOOP(4) Cole, Cox, Green, Wall | Green> MULTIPLE VENDORS INVOLVED | Stracener> I"m going to go with this because at least two of the affected vendors acknowledged a fix in the original advisory. | View |
633 | CVE-1999-0651 | Candidate | The rsh/rlogin service is running. | Proposed (19990804) | ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Christey | REJECT(1) Northcutt | Christey> aka "shell" on UNIX systems (at least Solaris) in the | /etc/inetd.conf file. | Frech> associated to: | XF:nt-rlogin(92) | XF:rsh-svc(114) | XF:rshd(2995) | View |
2714 | CVE-2000-1147 | Candidate | Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag. | Modified (20010116-01) | ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Cole | RECAST(1) LeBlanc | REVIEWING(1) Christey | Frech> XF:iis-isapi-asp-bo(5510) | Christey> Consult Microsoft on this one. | LeBlanc> This one was already fixed in several hotfixes when it was | found. I"m not sure what the content decision is on this. It is a valid | problem, but it was already fixed when announced. I will go along with | an accept vote once it is modified to show fixes. | View |
2660 | CVE-2000-1093 | Candidate | Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command. | Modified (20010417-01) | ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Christey | Frech> XF:aim-remote-bo(5732) | Christey> CD:SF-LOC as currently written suggests merging this with | CVE-2000-1094, since both describe buffer overflows in the | same software version. | Christey> Consider adding BID:2118 | View |
577 | CVE-1999-0595 | Candidate | A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded. | Proposed (19990728) | ACCEPT(2) Baker, Wall | MODIFY(1) Frech | NOOP(1) Northcutt | Frech> XF:nt-clearpage(216) | XF:reg-pagefile-clearing(2551) | View |
Page 807 of 20943, showing 5 records out of 104715 total, starting on record 4031, ending on 4035