CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3400 | CVE-2001-0587 | Candidate | deliver program in MMDF 2.43.3b in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command. | Modified (20020225-01) | ACCEPT(4) Baker, Bishop, Frech, Williams | NOOP(5) Christey, Cole, Foat, Wall, Ziese | Frech> CONFIRM:ftp://ftp.sco.com/SSE/sse072b.ltr | Christey> SCO fixed a number of mail-related issues. This is affected | by CD:SF-EXEC. There may be related CANs. | View |
747 | CVE-1999-0767 | Candidate | Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable. | Proposed (19991214) | ACCEPT(4) Baker, Blake, Cole, Dik | MODIFY(2) Frech, Stracener | REVIEWING(2) Christey, Prosser | Stracener> Add Ref: CIAC: J-069 | Frech> XF:sun-libc-lcmessages | Prosser> BID 268 is an additional reference for this one as it has info on the Sun | vulnerability. However, BID 268 also includes AIX in this vulnerability and | refs APARS issued to fix a vulnerability in various "nixs with the Natural | Language Service environmental variables NSLPATH and PATH_LOCALE depending | on the "nix, ref CERT CA-97.10, CVE-1999-0041. However, Georgi Guninski | reported a BO in AIX with LC_MESSAGES + mount, also refed in BID 268, so it | is possible the AIX APARs fix an earlier, similar vulnerability to the Sun | BO in LC_MESSAGES. This should probably be considered under a different | CAN. Any ideas? | Christey> Given that the buffer overflows in CVE-1999-0041 are NLSPATH | and PATH_LOCALE, I"d say that"s good evidence that this is not | the same problem. But a buffer overflow in libc in | LC_MESSAGES... We must ask if these are basically the same | codebase. | | ADDREF CIAC:J-069 | Christey> While the description indicates multiple programs, CD:SF-EXEC | does not apply because the vulnerability was in libc, and | rcp and ufsrestore were both statically linked against libc. | Thus CD:SF-LOC applies, and a single candidate is maintained | because the problem occurred in a library. | Dik> Sun bug 4240566 | Christey> I"m consulting with Casper Dik and Troy Bollinger to see if | this should be combined with the AIX buffer overflows for | LC_MESSAGES; current indications are that they should be | split. | Christey> For further consultation, consider this post, though it"s | associated with CVE-1999-0041: | BUGTRAQ:19970213 Linux NLSPATH buffer overflow | http://www.securityfocus.com/archive/1/6296 | Also add "NLSPATH" and "PATH_LOCALE" to the description to | facilitate search. | View |
1783 | CVE-2000-0205 | Candidate | Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients. | Proposed (20000322) | ACCEPT(4) Baker, Blake, Cole, Levy | MODIFY(1) Frech | NOOP(3) LeBlanc, Ozancin, Wall | Frech> XF:trendmicro-admin-command(4041) | View |
2154 | CVE-2000-0578 | Candidate | SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user. | Proposed (20000719) | ACCEPT(4) Baker, Blake, Cole, Levy | MODIFY(1) Frech | NOOP(7) Armstrong, Christey, LeBlanc, Magdych, Oliver, Ozancin, Wall | Frech> XF:sgi-mipspro-modify-files(5007) | CHANGE> [Cole changed vote from NOOP to ACCEPT] | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | Christey> SGI:20030605-01-A | URL:ftp://patches.sgi.com/support/free/security/advisories/20030605-01-A | View |
2202 | CVE-2000-0626 | Candidate | Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. | Proposed (20000803) | ACCEPT(4) Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, LeBlanc, Oliver, Ozancin | REVIEWING(1) Christey | Frech> XF:alibaba-get-dos(4934) | Christey> This is in a relatively old Nessus plugin, though the exploit | uses POST instead of GET. This was probably discovered | earlier than the references indicate. | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Wall> Found by Arne Vidstrom and found in multiple sources | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> See the POST comment in | http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2 | Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2 | | One poster says that a large number of sites are running | Alibaba (based on a netcraft report), but I"m not 100% | sure Netcraft"s doing a good job of identifying Alibaba | servers. | View |
Page 1014 of 20943, showing 5 records out of 104715 total, starting on record 5066, ending on 5070