CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3968  CVE-2001-1164  Candidate  Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.  Proposed (20020315)  ACCEPT(5) Armstrong, Baker, Cole, Green, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:unixware-uucp-bo(6762) | XF:unixware-uucp-uux-bo(6763) | XF:unixware-uucp-bnuconvert-bo(6764) | XF:unixware-uucp-uucico-bo(6765) | XF:unixware-uucp-uuxcmd-bo(6766) | XF:unixware-uucp-uuxqt-bo(6767)  View
3986  CVE-2001-1182  Candidate  Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.  Modified (20090302)  ACCEPT(5) Armstrong, Baker, Cole, Green, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey  Frech> XF:hpux-login-unauthorized-access(6860) | Christey> CIAC:L-114 | URL:http://ciac.llnl.gov/ciac/bulletins/l-114.shtml | BID:3068 | URL:http://online.securityfocus.com/bid/3068 | | This would appear to be a dupe of CVE-2001-0797, but the HP advisory | from CVE-2001-0797 is too vague to be certain. As quoted in | the CERT advisory for CVE-2001-0797, HP says: | "HP-UX does have a benign buffer overflow... [which] has been | fixed by HP." HP:HPSBUX0107-160 (CVE-2001-1182) states that | "The login(1) command allows restricted shell users to | circumvent security checks" which could be interpreted as | meaning that HP has found a slightly less-than-benign aspect | of the overflow, but since (a) the advisory says nothing about | overflows and (b) the advisory does not include any | cross-references, it cannot be clear. There is a difference | in the release dates as well, however, since the HP advisory | was released in July 2001 and this CAN was publicized in | December 2001, which may be sufficient evidence that the | problems are different. | | This probably is not the same issue in login as CVE-2001-0978, | since different patches are referenced in that CAN. | | There is insufficient information to know whether this is the | same issue as CVE-2001-0094 (kerberos library issues that | affect kerberized login).  View
3977  CVE-2001-1173  Candidate  Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.  Proposed (20020315)  ACCEPT(5) Armstrong, Baker, Cole, Green, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Christey> VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps) | URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:masqmail-gain-privileges(8717)  View
1792  CVE-2000-0214  Candidate  FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.  Proposed (20000322)  ACCEPT(5) Armstrong, Baker, Cole, Levy, Ozancin | MODIFY(1) Frech | NOOP(3) Blake, LeBlanc, Wall  Frech> XF:ftp-explorer-weak-pwd(4038)  View
826  CVE-1999-0846  Candidate  Denial of service in MDaemon 2.7 via a large number of connection attempts.  Proposed (19991208)  ACCEPT(5) Armstrong, Baker, Cole, Prosser, Stracener | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:mdaemon-dos | Christey> CVE-1999-0844 is confirmed by MDaemon at | http://mdaemon.deerfield.com/helpdesk/hotfix.cfm but there | is no apparent confirmation for this problem, even | though it was posted the same day. | Prosser> Looks like from a follow-on message on Bugtraq from Nobuo | <http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-11-28&msg=199912011604.HJI39569.BX-NOJ@lac.co.jp> Deerfield sent a reply about the | DoS problems in MDaemon 2.8.5, that also talks about fixing the 2.7 J DoS | that Nobuo initially reported. Can"t find the original message, so may have | been limited distro. Looks like an upgrade to the latest release might be | the final solution here.  View

Page 1062 of 20943, showing 5 records out of 104715 total, starting on record 5306, ending on 5310

Actions