CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5066  CVE-2002-0676  Entry  SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.        View
5067  CVE-2002-0677  Candidate  CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.  Modified (20071129)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Christey> XF:tooltalk-ttdbserverd-ttisclose-validation(9526) | URL:http://www.iss.net/security_center/static/9526.php | BID:5082 | URL:http://www.securityfocus.com/bid/5082 | | HP:HPSBUX0207-199 | URL:http://archives.neohapsis.com/archives/hp/2002-q3/0011.html | Note: while the HP advisory discusses "buffer overflows," | it specifically mentions CA-2002-20, and the text of the | advisory is included in vendor statements for the CERT-VU"s for both | ToolTalk issues covered by CA-2002-20. | | AIXAPAR:IY32368 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | AIXAPAR:IY32370 | URL:http://archives.neohapsis.com/archives/aix/2002-q3/0002.html | Christey> HP:HPSBUX0207-199 | URL:http://online.securityfocus.com/advisories/4290 | Christey> SGI:20021101-01-P | Christey> Sun confirmed via email to Matt Wojcik (of MITRE"s OVAL | project) that Sun alert 46022 also addresses this issue. | Frech> XF:tooltalk-ttdbserverd-ttisclose-validation(9526)  View
5068  CVE-2002-0678  Entry  CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.        View
5069  CVE-2002-0679  Entry  Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.        View
5070  CVE-2002-0680  Candidate  Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.  Proposed (20020726)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:goahead-directory-traversal(6046)  View

Page 1014 of 20943, showing 5 records out of 104715 total, starting on record 5066, ending on 5070

Actions