CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2644 | CVE-2000-1076 | Candidate | Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server. | Proposed (20001129) | ACCEPT(3) Baker, Frech, Mell | NOOP(2) Christey, Cole | Christey> Partial vendor acknowledgement at: | http://docs.iplanet.com/docs/manuals/cms/42/relnotes/release_notes.html | "By default, Administration Server administrator"s password | (also known as the SIE password) is stored in clear text in the | adm.conf file. | This does not usually pose a security threat because most | administrators use their Operating System"s security features to | ensure that the file is protected from other users." | View |
2646 | CVE-2000-1078 | Candidate | ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character. | Proposed (20001129) | ACCEPT(3) Baker, Frech, Mell | NOOP(2) Christey, Cole | Christey> The following post appears to describe the same problem, 7 | months earlier: | BUGTRAQ:20000310 ICQ remote DoS | View |
305 | CVE-1999-0306 | Candidate | buffer overflow in HP xlock program. | Proposed (19990714) | ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Prosser | NOOP(1) Shostack | REJECT(1) Christey | Prosser> This is another of those with multiple affected OSs. | Refs: CA-97.13, http://207.237.120.45/linux/xlock-exploit.txt, | HPSBUX9711-073, SGI 19970502-02-PX, Sun Bulletin 000150 | Christey> XF:hp-xlock points to SGI:19970502-02-PX which says this is | the same problem as in CERT:CA-97.13, which is CVE-1999-0038. | View |
165 | CVE-1999-0165 | Candidate | NFS cache poisoning. | Modified (20040811) | ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Shostack | NOOP(1) Prosser | REVIEWING(1) Christey | Shostack> need more data | Christey> need more refs | Christey> Add period to the end of the description. | View |
76 | CVE-1999-0076 | Candidate | Buffer overflow in wu-ftp from PASV command causes a core dump. | Modified (19990925-01) | ACCEPT(3) Baker, Frech, Ozancin | NOOP(1) Balinsky | REVIEWING(1) Christey | Balinsky> Don"t know what this is. Is this the LIST Core dump vulnerability? | Christey> Need to add more references and details. | View |
Page 949 of 20943, showing 5 records out of 104715 total, starting on record 4741, ending on 4745