CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1376 | CVE-1999-1396 | Candidate | Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash). | Modified (20020218-01) | ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:sun-integer-multiplication-access(7150) | Dik> sun bug: 1069072 1071053 | View |
1418 | CVE-1999-1438 | Candidate | Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments. | Proposed (20010912) | ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:bsd-binmail(515) | Dik> sun bug: 1047340 | Christey> Is there overlap between CVE-1999-1415 and CVE-1999-1438? | Both CERT advisories are vague. | View |
1138 | CVE-1999-1158 | Candidate | Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd. | Proposed (20010912) | ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | RECAST(1) Christey | Frech> XF:solaris-pam-bo(7432) | Dik> sun bug: 4018347 | Christey> These issues should be SPLIT per CD:SF-EXEC because the PAM | problem appears in different Solaris versions than | unix_scheme. | View |
297 | CVE-1999-0298 | Candidate | ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack. | Modified (20000524-01) | ACCEPT(4) Cole, Dik, Levy, Northcutt | MODIFY(1) Frech | NOOP(3) Baker, Christey, Shostack | Christey> ADDREF BID:1441 | URL:http://www.securityfocus.com/bid/1441 | Dik> If you run with "-ypset", then you"re always insecure. | With ypsetme, only root on the local host | can run ypset in Solaris 2.x+. | Probably true for SunOS 4, hence my vote. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> ADDREF XF:ypbind-ypset-root | CHANGE> [Dik changed vote from REVIEWING to ACCEPT] | Dik> This vulnerability does exist in SunOS 4.x in non default configurations. | In Solaris 2.x, the vulnerability only applies to files named "cache_binding" | and not all files ending in .2 | Both releases are not vulnerable in the default configuration (both | disabllow ypset by default which prevents this problem from occurring) | View |
1068 | CVE-1999-1088 | Candidate | Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges. | Proposed (20010912) | ACCEPT(4) Cole, Foat, Frech, Stracener | View |
Page 1041 of 20943, showing 5 records out of 104715 total, starting on record 5201, ending on 5205