CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
692 | CVE-1999-0712 | Candidate | A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable. | Proposed (19991214) | ACCEPT(4) Baker, Cole, Frech, Stracener | MODIFY(1) Blake | NOOP(1) Armstrong | REVIEWING(1) Christey | Blake> This obscurely-written advisory seems to state that COAS will make the | file world-readable, not that it allows the user to make it so. I hardly | think that allowing the user to turn off security is a vulnerability. | Christey> It"s difficult to write the description based on what"s in | the advisory. If COAS inadvertently changes permissions | without user confirmation, then it should be ACCEPTed with | appropriate modification to the description. | Christey> ADDREF BID:137 | CHANGE> [Armstrong changed vote from REVIEWING to NOOP] | View |
5228 | CVE-2002-0838 | Candidate | Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Frech, Wall | MODIFY(1) Cox | NOOP(1) Christey | Cox> Addref: RHSA-2002:211 | Christey> GENTOO:GLSA-200408-10 | URL:http://www.gentoo.org/security/en/glsa/glsa-200408-10.xml | View |
4762 | CVE-2002-0370 | Candidate | Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0. | Modified (20150106) | ACCEPT(4) Baker, Cole, Frech, Wall | NOOP(1) Cox | View | |
5619 | CVE-2002-1235 | Candidate | The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack. | Proposed (20030317) | ACCEPT(4) Baker, Cole, Frech, Wall | NOOP(1) Cox | Cox> Addref: REDHAT:RHSA-2002:250 | View |
2867 | CVE-2001-0046 | Candidate | The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities. | Modified (20061101) | ACCEPT(4) Baker, Cole, Frech, Wall | NOOP(1) Ziese | View |
Page 1023 of 20943, showing 5 records out of 104715 total, starting on record 5111, ending on 5115