CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2332  CVE-2000-0756  Candidate  Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(2) Frech, LeBlanc | REVIEWING(2) Christey, Wall  LeBlanc> - if a KB article, bulletin, or patch can be found, then | I"ll ACCEPT | Christey> This is the same as MS:MS01-012 (CVE-2001-0145) | See the Bugtraq post by Joel Moses: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Frech> XF:outlook-vcard-dos(5175) | XF:outlook-vcard-bo(6145) | Because there"s another more recent CAN linked to @stake and | Microsoft"s advisories, we"ll link both of our records to both | candiates until a final decision occurs. If a decision has been made | to promote the CVE-2001 entry, then enter my vote as a REJECT for | CVE-2000-0756. | Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175)  View
1820  CVE-2000-0242  Candidate  WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.  Proposed (20000412)  ACCEPT(2) Cole, Levy | NOOP(1) Baker | RECAST(1) Frech | REJECT(2) Christey, Magdych  Frech> Violation of fundamentum divisionis (that is, it"s more than one issue) and | a potential nitpick: | - windmail-fileread: allows remote attackers to read arbitrary files | - windmail-pipe-command: execute commands via shell metacharacters | - The conjunction "or" should be "and", if you decide to stick with one CAN. | Christey> As Andre basically said without naming content decisions, | CD:SF-LOC says this should be split. | | HOWEVER - the author of the product says that WindMail isn"t | supposed to be a CGI script, and says that the pipe | character problem is not related to Geocel. So should CVE | record when someone runs a program that wasn"t intended to | be a CGI? There may be a level of abstraction issue here. | Note that Perl and shell interpreters in CGI-BIN are | already mentioned in CVE-1999-0509. If we want to include | "using a program that wasn"t designed to be a CGI" as a | problem, we should have a separate candidate. | | See the author"s comments at: | http://www.securityfocus.com/templates/archive.pike?list=1&msg=3.0.5.32.20000331114325.013af680@mailhost.geocel.com | | which also claims that the original announcer hasn"t provided | any more details after the author was unable to reproduce the | problem. | CHANGE> [Magdych changed vote from REVIEWING to REJECT] | Magdych> After reviewing the author"s comments, I"m inclined to think that this is more of a misconfiguration than a vulnerability.  View
2331  CVE-2000-0755  Candidate  Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.  Proposed (20000921)  ACCEPT(2) Cole, Levy | NOOP(2) Baker, Wall | REJECT(2) Christey, Frech  Christey> DUPE CVE-2000-0730 | Also, the BID is wrong. | Frech> DUPE OF CVE-2000-0730 | Also, the BID is wrong.  View
2635  CVE-2000-1066  Candidate  The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.  Modified (20010119-01)  ACCEPT(2) Cole, Mell | MODIFY(1) Frech | NOOP(1) Renaud  Frech> XF:getnameinfo-dos(5454)  View
2577  CVE-2000-1008  Candidate  PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device.  Modified (20010116-01)  ACCEPT(2) Cole, Mell | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:palm-weak-encryption(5308)  View

Page 846 of 20943, showing 5 records out of 104715 total, starting on record 4226, ending on 4230

Actions