CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2644  CVE-2000-1076  Candidate  Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.  Proposed (20001129)  ACCEPT(3) Baker, Frech, Mell | NOOP(2) Christey, Cole  Christey> Partial vendor acknowledgement at: | http://docs.iplanet.com/docs/manuals/cms/42/relnotes/release_notes.html | "By default, Administration Server administrator"s password | (also known as the SIE password) is stored in clear text in the | adm.conf file. | This does not usually pose a security threat because most | administrators use their Operating System"s security features to | ensure that the file is protected from other users."  View
2646  CVE-2000-1078  Candidate  ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.  Proposed (20001129)  ACCEPT(3) Baker, Frech, Mell | NOOP(2) Christey, Cole  Christey> The following post appears to describe the same problem, 7 | months earlier: | BUGTRAQ:20000310 ICQ remote DoS  View
305  CVE-1999-0306  Candidate  buffer overflow in HP xlock program.  Proposed (19990714)  ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Prosser | NOOP(1) Shostack | REJECT(1) Christey  Prosser> This is another of those with multiple affected OSs. | Refs: CA-97.13, http://207.237.120.45/linux/xlock-exploit.txt, | HPSBUX9711-073, SGI 19970502-02-PX, Sun Bulletin 000150 | Christey> XF:hp-xlock points to SGI:19970502-02-PX which says this is | the same problem as in CERT:CA-97.13, which is CVE-1999-0038.  View
165  CVE-1999-0165  Candidate  NFS cache poisoning.  Modified (20040811)  ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Shostack | NOOP(1) Prosser | REVIEWING(1) Christey  Shostack> need more data | Christey> need more refs | Christey> Add period to the end of the description.  View
76  CVE-1999-0076  Candidate  Buffer overflow in wu-ftp from PASV command causes a core dump.  Modified (19990925-01)  ACCEPT(3) Baker, Frech, Ozancin | NOOP(1) Balinsky | REVIEWING(1) Christey  Balinsky> Don"t know what this is. Is this the LIST Core dump vulnerability? | Christey> Need to add more references and details.  View

Page 949 of 20943, showing 5 records out of 104715 total, starting on record 4741, ending on 4745

Actions