CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2138 | CVE-2000-0562 | Candidate | BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower. | Proposed (20000712) | ACCEPT(3) Armstrong, Cole, Levy | MODIFY(2) Baker, Frech | NOOP(1) Ozancin | REVIEWING(1) Christey | Levy> What do others think? Should this be a vuln? I can see the argument | that some features are simply not available unless you use the maximum | security settings. | Christey> At the very least, this needs to be modified to state that | this problem/concern applies to high ports in general, not | just Back orifice. | | The Bugtraq poster claims that BlackICE "shuts down" the port, | but only *after* some initial traffic "leaks" out. This may | be by design, but it does mean that there is a small window | of opportunity in which BlackICE may not work "as | advertised," even at lower security settings. | Christey> XF:blackice-security-level-nervous | BID:1389 | Frech> XF:blackice-security-level-nervous(4777) | CHANGE> [Levy changed vote from REVIEWING to ACCEPT] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Baker> I accept it more as a security exposure, than a real vulnerability. | It performs just as any other "firewall" or IDS product can be configured to | allow traffic without notifying the user. You can adjust settings on | any product that allow traffic that other people or organizations would | find unacceptable. So, as long as it is reflected that this is more of | a configuration that allows such traffic as opposed to a defective | or improperly functioning software issue, I don"t have a problem with | it. | View |
2621 | CVE-2000-1052 | Candidate | Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet. | Proposed (20001129) | ACCEPT(3) Armstrong, Cole, Mell | MODIFY(1) Frech | Frech> XF:allaire-jrun-ssifilter-url(5405) | View |
285 | CVE-1999-0286 | Candidate | In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages. | Proposed (19990714) | ACCEPT(3) Armstrong, Cole, Shostack | MODIFY(3) Blake, Levy, Wall | NOOP(5) Baker, Bishop, Landfield, Northcutt, Ozancin | REJECT(1) Frech | REVIEWING(1) Christey | Wall> In some NT web servers, appending a dot at the end of a URL may | allows attackers to read source code for active pages. | Source: MS Knowledge Base Article Q163485 - "Active Server Pages Script Appears | in Browser" | Frech> In the meantime, reword description as "Windows NT" (trademark issue) | Christey> Q163485 does not refer to a space, it refers to a dot. | However, I don"t have other references. | | Reading source code with a dot appended is in CVE-1999-0154, | which will be proposed. A subsequent bug similar to the | dot bug is CVE-1999-0253. | Levy> NTBUGTRAQ: http://www.securityfocus.com/archive/2/22014 | NTBUGTRAQ: http://www.securityfocus.com/archive/2/22019 | BID 273 | Blake> Reference: http://www.allaire.com/handlers/index.cfm?ID=10967 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> BID articles) | View |
832 | CVE-1999-0852 | Candidate | IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin. | Proposed (19991208) | ACCEPT(3) Armstrong, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Prosser | Frech> XF:websphere-protect | View |
842 | CVE-1999-0862 | Candidate | Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file. | Proposed (19991208) | ACCEPT(3) Armstrong, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Prosser | Frech> XF:postgresql-insecure-perms | View |
Page 918 of 20943, showing 5 records out of 104715 total, starting on record 4586, ending on 4590