CVE List

Id CVE No. Status Description Phase Votes Comments Actions
821  CVE-1999-0841  Candidate  Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.  Modified (20071022)  ACCEPT(5) Armstrong, Baker, Cole, Dik, Stracener | MODIFY(1) Frech | REVIEWING(1) Prosser  Frech> XF:cde-mailtool-bo | Dik> bug 4163471 | (Root access is only possible when mail is send to root and he | uses dtmail to read it)  View
3541  CVE-2001-0734  Candidate  Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.  Proposed (20011012)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Frech | NOOP(1) Wall    View
3731  CVE-2001-0925  Candidate  The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.  Proposed (20020131)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Green | NOOP(2) Christey, Wall | REJECT(1) Frech  Frech> I"m using both candidates until we decide if it is a dupe, | and then which | candidate to deprecate. | Christey> BUGTRAQ:20010615 TSLSA-2001-0010 - Apache | URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0180.html | Christey> CVE-2001-0925 and CVE-2001-0729 are different issues. | CVE-2001-0925 only applies to versions before 1.3.19, whereas | CVE-2001-0729 applies to 1.3.20, and only Windows. | | The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3 | specifically mentions these CANs separately.  View
3521  CVE-2001-0713  Candidate  Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.  Modified (20050702)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:sendmail-setregid-gain-privileges(7192) | Christey> Consider adding BID:3377 | Christey> BID:3377 | URL:http://www.securityfocus.com/bid/3377  View
3523  CVE-2001-0715  Candidate  Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.  Modified (20050704)  ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:sendmail-debug-gain-information(7191) | Christey> ADDREF SGI:20011101-01-I | Christey> CIAC:M-020 | URL:http://ciac.llnl.gov/ciac/bulletins/m-020.shtml | HP:HPSBUX0201-179 | URL:http://www.securityfocus.com/advisories/3794 | BID:3898 | URL:http://www.securityfocus.com/bid/3898 | It *might* be that HP:HPSBUX0201-179 addresses this, but the | advisory is too vague to be certain. | URL:http://www.securityfocus.com/advisories/3794  View

Page 1057 of 20943, showing 5 records out of 104715 total, starting on record 5281, ending on 5285

Actions