CVE List

Id CVE No. Status Description Phase Votes Comments Actions
692  CVE-1999-0712  Candidate  A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.  Proposed (19991214)  ACCEPT(4) Baker, Cole, Frech, Stracener | MODIFY(1) Blake | NOOP(1) Armstrong | REVIEWING(1) Christey  Blake> This obscurely-written advisory seems to state that COAS will make the | file world-readable, not that it allows the user to make it so. I hardly | think that allowing the user to turn off security is a vulnerability. | Christey> It"s difficult to write the description based on what"s in | the advisory. If COAS inadvertently changes permissions | without user confirmation, then it should be ACCEPTed with | appropriate modification to the description. | Christey> ADDREF BID:137 | CHANGE> [Armstrong changed vote from REVIEWING to NOOP]  View
5228  CVE-2002-0838  Candidate  Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf.  Proposed (20030317)  ACCEPT(4) Baker, Cole, Frech, Wall | MODIFY(1) Cox | NOOP(1) Christey  Cox> Addref: RHSA-2002:211 | Christey> GENTOO:GLSA-200408-10 | URL:http://www.gentoo.org/security/en/glsa/glsa-200408-10.xml  View
4762  CVE-2002-0370  Candidate  Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.  Modified (20150106)  ACCEPT(4) Baker, Cole, Frech, Wall | NOOP(1) Cox    View
5619  CVE-2002-1235  Candidate  The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2) kadmind in KTH Kerberos 4 (eBones) before 1.2.1, and (3) kadmind in KTH Kerberos 5 (Heimdal) before 0.5.1 when compiled with Kerberos 4 support, does not properly verify the length field of a request, which allows remote attackers to execute arbitrary code via a buffer overflow attack.  Proposed (20030317)  ACCEPT(4) Baker, Cole, Frech, Wall | NOOP(1) Cox  Cox> Addref: REDHAT:RHSA-2002:250  View
2867  CVE-2001-0046  Candidate  The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.  Modified (20061101)  ACCEPT(4) Baker, Cole, Frech, Wall | NOOP(1) Ziese    View

Page 1023 of 20943, showing 5 records out of 104715 total, starting on record 5111, ending on 5115

Actions