CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1993  CVE-2000-0415  Candidate  Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.  Proposed (20000615)  ACCEPT(3) Levy, Ozancin, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cole, Stracener | REJECT(1) LeBlanc  LeBlanc> The poster re-discovered a vulnerability we patched two years | ago, in | http://www.microsoft.com/technet/security/bulletin/ms98-008.asp | Microsoft posted a response to BugTraq when this one went | public, and reminded them that we"d already patched it. | | BTW, I think we want to try and pay attention to follow-ups to | these threads in order to minimize noise in the process. | Christey> Based on David"s comments, this is covered by CVE-1999-0002. | However, that candidate may wind up being SPLIT, so I will | keep this one around for the moment. | | With respect to watching followups, we are relying quite | a bit on other data feeds instead of doing our own reviews | of all the different data sources. The data feeds may report | these problems as new before corrections are posted. | Followups do often lend additional information to the | candidates, and as is the case with this one, we will | often catch the discrepancy before the candidate becomes an | official entry, whether by MITRE"s own analysis or by that | of other Board members. | Frech> XF:outlook-image-long-filename  View
2007  CVE-2000-0429  Candidate  A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.  Proposed (20000615)  ACCEPT(3) Ozancin, Prosser, Stracener | MODIFY(2) Frech, Levy | NOOP(2) Baker, Cole  Levy> Reference: BID 1153 | Frech> XF:cart32-admin-password  View
651  CVE-1999-0670  Candidate  Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.  Proposed (19991208)  ACCEPT(3) Ozancin, Prosser, Wall | MODIFY(2) Frech, Stracener | REJECT(2) Baker, Cole  Frech> XF:ie-eyedog-bo | Cole> Based on the references and information listed this is the same as | CVE-1999-0669 | Stracener> Add Ref: MSKB Q240308 | Baker> Duplicate  View
564  CVE-1999-0582  Candidate  A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.  Proposed (19990721)  ACCEPT(3) Ozancin, Shostack, Wall | MODIFY(2) Baker, Frech | REJECT(1) Northcutt  Northcutt> The definition is? | Baker> Maybe a rewording of this one too. I think most people would agree on | some "minimum" policies like 3-5 bad attempts lockout for an hour or | until the administrator unlocks the account. | Suggested rewrite - | A Windows NT account policy does not enforce reasonable minimum | security-critical settings for lockouts, e.g. lockout duration, | lockout after bad logon attempts, etc. | Ozancin> with reservations | What is appropriate? | Frech> XF:nt-thres-lockout | XF:nt-lock-duration | XF:nt-lock-window | XF:nt-perm-lockout | XF:lockout-disabled  View
4819  CVE-2002-0427  Candidate  Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges.  Proposed (20020611)  ACCEPT(4) Alderson, Baker, Cole, Frech | MODIFY(1) Cox | NOOP(2) Foat, Wall  Cox> The description should say "improved mod_frontpage" as there | are two Frontpage modules for Apache, the offical one and this one.  View

Page 989 of 20943, showing 5 records out of 104715 total, starting on record 4941, ending on 4945

Actions