CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1586  CVE-2000-0008  Candidate  FTPPro allows local users to read sensitive information, which is stored in plain text.  Proposed (20000111)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy  Frech> XF:ftppro-plaintext-information | Christey> ADDREF BID:1790 | ADDREF URL:http://www.securityfocus.com/bid/1790  View
1583  CVE-2000-0005  Candidate  HP-UX aserver program allows local users to gain privileges via a symlink attack.  Modified (20090302)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | RECAST(1) Christey | REVIEWING(1) Levy  Christey> BUGTRAQ:20000102 "HPUX Aserver revisited." indicates that two | different versions of aserver have symlink problems, but with | different files. So CD:SF-LOC says we should split this. | Frech> XF:hp-aserver | Christey> BID:1928 and BID:1930? Which one is being described in | this candidate? | Christey> BID:1930  View
808  CVE-1999-0828  Candidate  UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.  Modified (20000121-01)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Cole, Frech | REVIEWING(2) Christey, Prosser  Cole> This is BID 850. | Christey> See comments on CVE-1999-0988. Perhaps these two should be | merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a | loosely alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:sco-pkg-dacread-fileread  View
1597  CVE-2000-0019  Candidate  IMail POP3 daemon uses weak encryption, which allows local users to read files.  Proposed (20000111)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Christey  Frech> XF:imail-passwords | Levy> BID 880 | Christey> BUGTRAQ:19990304 IMAIL password recovery is trivial. | http://www.securityfocus.com/archive/1/12750 | Christey> Add version numbers (5.0 through 5.08)  View
1599  CVE-2000-0021  Candidate  Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.  Modified (20060616)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Christey  Frech> XF:http-cgi-lotus-domino | Levy> BID 881 | Christey> BID:881  View

Page 906 of 20943, showing 5 records out of 104715 total, starting on record 4526, ending on 4530

Actions