CVE List

Id CVE No. Status Description Phase Votes Comments Actions
234  CVE-1999-0235  Candidate  Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.  Modified (19991220-01)  ACCEPT(3) Hill, Northcutt, Prosser | MODIFY(1) Frech | REJECT(2) Baker, Christey  Frech> XF:http-ncsa-longurl | Christey> CVE-1999-0235 has the same ref"s as CVE-1999-0267 | Baker> Not to mention, the X-force listings of http-ncsa-longurl and http-port both | refer to the same problem. This should be rejected as 1999-0267 is the same problem.  View
2065  CVE-2000-0487  Candidate  The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability.  Proposed (20000712)  ACCEPT(3) LeBlanc, Levy, Wall | MODIFY(1) Frech | NOOP(1) Ozancin  Frech> XF:ms-protected-store(4589)  View
30  CVE-1999-0030  Candidate  root privileges via buffer overflow in xlock command on SGI IRIX systems.  Proposed (19990623)  ACCEPT(3) Levy, Ozancin, Prosser | NOOP(1) Baker | RECAST(1) Frech | REJECT(1) Christey  Frech> XF:xlock-bo (also add) | As per xlock-bo, also appears on AIX, BSDI, DG/UX, FreeBSD, Solaris, and | several Linii. | Also, don"t you mean to cite SGI:19970502-02-PX? The one you list is | login/scheme. | Levy> Notice that this xlock overflow is the same as in | CA-97.13. CA-97.21 simply is a reminder. | Christey> As pointed out by Elias, CA-97.21 states: "For more | information about vulnerabilities in xlock... see CA-97.13" | CA-97.13 = CVE-1999-0038. | This may also be a duplicate with CVE-1999-0306. | | See exploits at: | | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418394&w=2 | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418404&w=2 | | Sun also has this problem, at | http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/150&type=0&nav=sec.sba  View
2028  CVE-2000-0450  Candidate  Vulnerability in bbd server in Big Brother System and Network Monitor allows an attacker to execute arbitrary commands.  Proposed (20000615)  ACCEPT(3) Levy, Ozancin, Stracener | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | RECAST(1) LeBlanc  LeBlanc> I have no idea what this one is talking about from the description. I also | don"t think it involves "Network Monitor", which is a component of Windows | NT/Windows 2000. This should be clarified. | Frech> XF:big-brother-bbd-bo | Christey> The original advisory, as forwarded to Bugtraq, does not | provide any details, so the description is necessarily vague. | Also, the home page at http://bb4.com has it referring to | itself as "Big Brother System and Network Monitor," so | "Network Monitor" is apparently part of the name of the product. | | Change this description to mention version 1.4g, to distinguish | from other Big Brother vulnerabilities.  View
2012  CVE-2000-0434  Candidate  The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers.  Proposed (20000615)  ACCEPT(3) Levy, Ozancin, Stracener | MODIFY(1) Frech | NOOP(3) Cole, LeBlanc, Wall  Frech> XF:http-cgi-allmanage-plaintext-admin  View

Page 988 of 20943, showing 5 records out of 104715 total, starting on record 4936, ending on 4940

Actions