CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
542 | CVE-1999-0554 | Candidate | NFS exports system-critical data to the world, e.g. / or a password file. | Proposed (19990803) | ACCEPT(2) Northcutt, Wall | NOOP(1) Baker | REVIEWING(1) Christey | Christey> A content decision (CD:CF-DATA) needs to be reviewed | and accepted by the Editorial Board in order to resolve | this question. | View |
449 | CVE-1999-0450 | Candidate | In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | Modified (20090622) | ACCEPT(2) Ozancin, Wall | NOOP(2) Baker, Christey | REJECT(2) Frech, LeBlanc | Frech> Can"t find in database. | Christey> This looks like another discovery of CVE-2000-0071 | LeBlanc> - I just tried to repro this based on the BUGTRAQ vuln information, | and it does not repro - | GET /bogus.pl HTTP/1.0 | HTTP/1.1 404 Object Not Found | Server: Microsoft-IIS/5.0 | Date: Thu, 05 Oct 2000 21:04:20 GMT | Content-Length: 3243 | Content-Type: text/html | No path is returned whatsoever. This may have been a problem on some version | of IIS in the past, but the BUGTRAQ ID says all versions are vulnerable. | Let"s try and figure out what version had the problem, whether it is | intrinsic to IIS or the result of adding a 3rd party implementation of perl, | and when it got fixed, then we can try again. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Christey> Add "no-such-file.pl" as an example to the desc, to facilitate | search (it"s used by CGI scanners and in the original example) | View |
532 | CVE-1999-0535 | Candidate | A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. | Proposed (19990721) | ACCEPT(2) Shostack, Wall | MODIFY(2) Baker, Frech | RECAST(2) Northcutt, Ozancin | Northcutt> inappropriate implies there is appropriate. As a guy who has been | monitoring | networks for years I have deep reservations about justiying the existance | of any fixed cleartext password. For appropriate to exist, some "we" would | have to establish some criteria for appropriate passwords. | Baker> Perhaps this could be re-worded a bit. The CVE CVE-1999-00582 | specifies "...settings for lockouts". To remain consistent with the | other, maybe it should specify "...settings for passwords" I think | most people would agree that passwords should be at least 8 | characters; contain letters (upper and lowercase), numbers and at | least one non-alphanumeric; should only be good a limited time 30-90 | days; and should not contain character combinations from user"s prior | 2 or 3 passwords. | Suggested rewrite - | A Windows NT account policy does not enforce reasonable minimum | security-critical settings for passwords, e.g. passwords of sufficient | length, periodic required password changes, or new password uniqueness | Ozancin> What is appropriate? | Frech> XF:nt-autologonpwd | XF:nt-pwlen | XF:nt-maxage | XF:nt-minage | XF:nt-pw-history | XF:nt-user-pwnoexpire | XF:nt-unknown-pwdfilter | XF:nt-pwd-never-expire | XF:nt-pwd-nochange | XF:nt-pwdcache-enable | XF:nt-guest-change-passwords | View |
559 | CVE-1999-0577 | Candidate | A Windows NT system"s file audit policy does not log an event success or failure for non-critical files or directories. | Proposed (19990721) | ACCEPT(2) Shostack, Wall | MODIFY(3) Baker, Frech, Ozancin | REJECT(1) Northcutt | Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Perhaps only failure should be logged. | Frech> XF:nt-object-audit | CHANGE> [Baker changed vote from REVIEWING to MODIFY] | Baker> Failure on non-critical files is what should be monitored. | View |
973 | CVE-1999-0993 | Candidate | Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. | Proposed (19991222) | ACCEPT(2) Stracener, Wall | MODIFY(1) Frech | NOOP(2) Baker, Cole | REJECT(1) LeBlanc | Frech> XF:exchange-acl-changes(3916) | LeBlanc> Not a vulnerability | View |
Page 890 of 20943, showing 5 records out of 104715 total, starting on record 4446, ending on 4450