CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1993 | CVE-2000-0415 | Candidate | Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name. | Proposed (20000615) | ACCEPT(3) Levy, Ozancin, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cole, Stracener | REJECT(1) LeBlanc | LeBlanc> The poster re-discovered a vulnerability we patched two years | ago, in | http://www.microsoft.com/technet/security/bulletin/ms98-008.asp | Microsoft posted a response to BugTraq when this one went | public, and reminded them that we"d already patched it. | | BTW, I think we want to try and pay attention to follow-ups to | these threads in order to minimize noise in the process. | Christey> Based on David"s comments, this is covered by CVE-1999-0002. | However, that candidate may wind up being SPLIT, so I will | keep this one around for the moment. | | With respect to watching followups, we are relying quite | a bit on other data feeds instead of doing our own reviews | of all the different data sources. The data feeds may report | these problems as new before corrections are posted. | Followups do often lend additional information to the | candidates, and as is the case with this one, we will | often catch the discrepancy before the candidate becomes an | official entry, whether by MITRE"s own analysis or by that | of other Board members. | Frech> XF:outlook-image-long-filename | View |
2007 | CVE-2000-0429 | Candidate | A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands. | Proposed (20000615) | ACCEPT(3) Ozancin, Prosser, Stracener | MODIFY(2) Frech, Levy | NOOP(2) Baker, Cole | Levy> Reference: BID 1153 | Frech> XF:cart32-admin-password | View |
651 | CVE-1999-0670 | Candidate | Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. | Proposed (19991208) | ACCEPT(3) Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(2) Baker, Cole | Frech> XF:ie-eyedog-bo | Cole> Based on the references and information listed this is the same as | CVE-1999-0669 | Stracener> Add Ref: MSKB Q240308 | Baker> Duplicate | View |
564 | CVE-1999-0582 | Candidate | A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. | Proposed (19990721) | ACCEPT(3) Ozancin, Shostack, Wall | MODIFY(2) Baker, Frech | REJECT(1) Northcutt | Northcutt> The definition is? | Baker> Maybe a rewording of this one too. I think most people would agree on | some "minimum" policies like 3-5 bad attempts lockout for an hour or | until the administrator unlocks the account. | Suggested rewrite - | A Windows NT account policy does not enforce reasonable minimum | security-critical settings for lockouts, e.g. lockout duration, | lockout after bad logon attempts, etc. | Ozancin> with reservations | What is appropriate? | Frech> XF:nt-thres-lockout | XF:nt-lock-duration | XF:nt-lock-window | XF:nt-perm-lockout | XF:lockout-disabled | View |
4819 | CVE-2002-0427 | Candidate | Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges. | Proposed (20020611) | ACCEPT(4) Alderson, Baker, Cole, Frech | MODIFY(1) Cox | NOOP(2) Foat, Wall | Cox> The description should say "improved mod_frontpage" as there | are two Frontpage modules for Apache, the offical one and this one. | View |
Page 989 of 20943, showing 5 records out of 104715 total, starting on record 4941, ending on 4945