CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
821 | CVE-1999-0841 | Candidate | Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type. | Modified (20071022) | ACCEPT(5) Armstrong, Baker, Cole, Dik, Stracener | MODIFY(1) Frech | REVIEWING(1) Prosser | Frech> XF:cde-mailtool-bo | Dik> bug 4163471 | (Root access is only possible when mail is send to root and he | uses dtmail to read it) | View |
3541 | CVE-2001-0734 | Candidate | Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine. | Proposed (20011012) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Frech | NOOP(1) Wall | View | |
3731 | CVE-2001-0925 | Candidate | The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. | Proposed (20020131) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Green | NOOP(2) Christey, Wall | REJECT(1) Frech | Frech> I"m using both candidates until we decide if it is a dupe, | and then which | candidate to deprecate. | Christey> BUGTRAQ:20010615 TSLSA-2001-0010 - Apache | URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0180.html | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately. | View |
3521 | CVE-2001-0713 | Candidate | Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function. | Modified (20050702) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:sendmail-setregid-gain-privileges(7192) | Christey> Consider adding BID:3377 | Christey> BID:3377 | URL:http://www.securityfocus.com/bid/3377 | View |
3523 | CVE-2001-0715 | Candidate | Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode. | Modified (20050704) | ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:sendmail-debug-gain-information(7191) | Christey> ADDREF SGI:20011101-01-I | Christey> CIAC:M-020 | URL:http://ciac.llnl.gov/ciac/bulletins/m-020.shtml | HP:HPSBUX0201-179 | URL:http://www.securityfocus.com/advisories/3794 | BID:3898 | URL:http://www.securityfocus.com/bid/3898 | It *might* be that HP:HPSBUX0201-179 addresses this, but the | advisory is too vague to be certain. | URL:http://www.securityfocus.com/advisories/3794 | View |
Page 1057 of 20943, showing 5 records out of 104715 total, starting on record 5281, ending on 5285