CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3400  CVE-2001-0587  Candidate  deliver program in MMDF 2.43.3b in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.  Modified (20020225-01)  ACCEPT(4) Baker, Bishop, Frech, Williams | NOOP(5) Christey, Cole, Foat, Wall, Ziese  Frech> CONFIRM:ftp://ftp.sco.com/SSE/sse072b.ltr | Christey> SCO fixed a number of mail-related issues. This is affected | by CD:SF-EXEC. There may be related CANs.  View
747  CVE-1999-0767  Candidate  Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.  Proposed (19991214)  ACCEPT(4) Baker, Blake, Cole, Dik | MODIFY(2) Frech, Stracener | REVIEWING(2) Christey, Prosser  Stracener> Add Ref: CIAC: J-069 | Frech> XF:sun-libc-lcmessages | Prosser> BID 268 is an additional reference for this one as it has info on the Sun | vulnerability. However, BID 268 also includes AIX in this vulnerability and | refs APARS issued to fix a vulnerability in various "nixs with the Natural | Language Service environmental variables NSLPATH and PATH_LOCALE depending | on the "nix, ref CERT CA-97.10, CVE-1999-0041. However, Georgi Guninski | reported a BO in AIX with LC_MESSAGES + mount, also refed in BID 268, so it | is possible the AIX APARs fix an earlier, similar vulnerability to the Sun | BO in LC_MESSAGES. This should probably be considered under a different | CAN. Any ideas? | Christey> Given that the buffer overflows in CVE-1999-0041 are NLSPATH | and PATH_LOCALE, I"d say that"s good evidence that this is not | the same problem. But a buffer overflow in libc in | LC_MESSAGES... We must ask if these are basically the same | codebase. | | ADDREF CIAC:J-069 | Christey> While the description indicates multiple programs, CD:SF-EXEC | does not apply because the vulnerability was in libc, and | rcp and ufsrestore were both statically linked against libc. | Thus CD:SF-LOC applies, and a single candidate is maintained | because the problem occurred in a library. | Dik> Sun bug 4240566 | Christey> I"m consulting with Casper Dik and Troy Bollinger to see if | this should be combined with the AIX buffer overflows for | LC_MESSAGES; current indications are that they should be | split. | Christey> For further consultation, consider this post, though it"s | associated with CVE-1999-0041: | BUGTRAQ:19970213 Linux NLSPATH buffer overflow | http://www.securityfocus.com/archive/1/6296 | Also add "NLSPATH" and "PATH_LOCALE" to the description to | facilitate search.  View
1783  CVE-2000-0205  Candidate  Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients.  Proposed (20000322)  ACCEPT(4) Baker, Blake, Cole, Levy | MODIFY(1) Frech | NOOP(3) LeBlanc, Ozancin, Wall  Frech> XF:trendmicro-admin-command(4041)  View
2154  CVE-2000-0578  Candidate  SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user.  Proposed (20000719)  ACCEPT(4) Baker, Blake, Cole, Levy | MODIFY(1) Frech | NOOP(7) Armstrong, Christey, LeBlanc, Magdych, Oliver, Ozancin, Wall  Frech> XF:sgi-mipspro-modify-files(5007) | CHANGE> [Cole changed vote from NOOP to ACCEPT] | CHANGE> [Magdych changed vote from REVIEWING to NOOP] | Christey> SGI:20030605-01-A | URL:ftp://patches.sgi.com/support/free/security/advisories/20030605-01-A  View
2202  CVE-2000-0626  Candidate  Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.  Proposed (20000803)  ACCEPT(4) Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, LeBlanc, Oliver, Ozancin | REVIEWING(1) Christey  Frech> XF:alibaba-get-dos(4934) | Christey> This is in a relatively old Nessus plugin, though the exploit | uses POST instead of GET. This was probably discovered | earlier than the references indicate. | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Wall> Found by Arne Vidstrom and found in multiple sources | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> See the POST comment in | http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2 | Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2 | | One poster says that a large number of sites are running | Alibaba (based on a netcraft report), but I"m not 100% | sure Netcraft"s doing a good job of identifying Alibaba | servers.  View

Page 1014 of 20943, showing 5 records out of 104715 total, starting on record 5066, ending on 5070

Actions