CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1586 | CVE-2000-0008 | Candidate | FTPPro allows local users to read sensitive information, which is stored in plain text. | Proposed (20000111) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy | Frech> XF:ftppro-plaintext-information | Christey> ADDREF BID:1790 | ADDREF URL:http://www.securityfocus.com/bid/1790 | View |
1583 | CVE-2000-0005 | Candidate | HP-UX aserver program allows local users to gain privileges via a symlink attack. | Modified (20090302) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | RECAST(1) Christey | REVIEWING(1) Levy | Christey> BUGTRAQ:20000102 "HPUX Aserver revisited." indicates that two | different versions of aserver have symlink problems, but with | different files. So CD:SF-LOC says we should split this. | Frech> XF:hp-aserver | Christey> BID:1928 and BID:1930? Which one is being described in | this candidate? | Christey> BID:1930 | View |
808 | CVE-1999-0828 | Candidate | UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission. | Modified (20000121-01) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Cole, Frech | REVIEWING(2) Christey, Prosser | Cole> This is BID 850. | Christey> See comments on CVE-1999-0988. Perhaps these two should be | merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a | loosely alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:sco-pkg-dacread-fileread | View |
1597 | CVE-2000-0019 | Candidate | IMail POP3 daemon uses weak encryption, which allows local users to read files. | Proposed (20000111) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Christey | Frech> XF:imail-passwords | Levy> BID 880 | Christey> BUGTRAQ:19990304 IMAIL password recovery is trivial. | http://www.securityfocus.com/archive/1/12750 | Christey> Add version numbers (5.0 through 5.08) | View |
1599 | CVE-2000-0021 | Candidate | Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin. | Modified (20060616) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Christey | Frech> XF:http-cgi-lotus-domino | Levy> BID 881 | Christey> BID:881 | View |
Page 906 of 20943, showing 5 records out of 104715 total, starting on record 4526, ending on 4530