CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2121 | CVE-2000-0544 | Candidate | Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length. | Proposed (20000712) | ACCEPT(2) LeBlanc, Levy | MODIFY(1) Frech | NOOP(1) Ozancin | REVIEWING(2) Christey, Wall | Frech> XF;nt-smb-request-dos(4600) | Christey> Consult with Microsoft to see if this is MS:MS00-066 | Christey> ADDREF MS:MS00-066 | (confirmed offline with David LeBlanc) | Subsequently, add BID:1673 and XF:win2k-rpc-dos(5222) | View |
1822 | CVE-2000-0244 | Candidate | The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication. | Proposed (20000412) | ACCEPT(2) Levy, Magdych | MODIFY(1) Frech | NOOP(2) Baker, Cole | Frech> XF:citrix-encryption | View |
2139 | CVE-2000-0563 | Candidate | The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) Christey, Wall | REVIEWING(1) LeBlanc | Christey> Confirmed by Scott Culp, but this only applies to | outdated/unsupported versions of the JVM. | Frech> XF:macos-java-security-ignored(5052) | Christey> Consult with Microsoft to ensure that this is fixed by | MS:MS00-059. If so, then this might not just be in MacOS. | View |
1998 | CVE-2000-0420 | Candidate | The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data. | Proposed (20000615) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) Cole, Stracener | REJECT(1) LeBlanc | REVIEWING(1) Wall | LeBlanc> This is not a vulnerability. It is essentially an advisory on best | practices. Also, the description is extremely inaccurate. If I weren"t | intimately familiar with the issue, I would not be able to understand it | from this. Syskey, when applied at lower levels, has well-documented | limitations. | Stracener> "..to recover" | Frech> XF:win2k-syskey-default-configuration | Change "tor ecover" to "to recover" | View |
2054 | CVE-2000-0476 | Candidate | xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | Frech> XF:xterm-control-characters-dos(4987) | View |
Page 885 of 20943, showing 5 records out of 104715 total, starting on record 4421, ending on 4425