CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4869 | CVE-2002-0477 | Candidate | Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand. | Proposed (20020611) | ACCEPT(5) Baker, Cole, Frech, Green, Wall | NOOP(2) Cox, Foat | REVIEWING(1) Christey | Christey> Is swf_clear.html *really* related to standalone_update.htm? | Or is the former really talking about a third issue related to | a virus? standalone_update.htm is clearly fscommand ("exec"). | It has an "Additional information" statement that says: | "For a description of the potential issue with the previous | stand-alone player, please refer to [swf_clear.htm]" | | I interpret "the previous stand-alone player" as meaning "the player | that we are updating with this advisory." Since we know that | standalone_update.htm is exec, this implies that swf_clear.htm is | really the exec issue. However, swf_clear.html doesn"t | mention fscommand ("exec") AT ALL, which casts doubt or at | least uncertainty as to my conclusions. | | swf_clear.html links back to standalone_update.htm, so at | least the references are circular. | | At least it"s pretty clear that this issue is different from | CVE-2002-0476. | | Email inquiry sent to Macromedia on June 13, 2002. | View |
2578 | CVE-2000-1009 | Candidate | dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program. | Proposed (20001129) | ACCEPT(5) Baker, Cole, Frech, Mell, Renaud | NOOP(1) Christey | Christey> http://www.redhat.com/support/errata/RHSA-2000-100.html | ADDREF BUGTRAQ:20001103 Trustix Security Advisory - dump | http://archives.neohapsis.com/archives/bugtraq/2000-11/0026.html | Christey> CERT-VN:VU#153653 | URL:http://www.kb.cert.org/vuls/id/153653 | View |
3259 | CVE-2001-0441 | Candidate | Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header. | Proposed (20010524) | ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(1) Wall | View | |
3275 | CVE-2001-0458 | Candidate | Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands. | Proposed (20010524) | ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(1) Wall | View | |
3267 | CVE-2001-0450 | Candidate | Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name. | Proposed (20010524) | ACCEPT(5) Baker, Cole, Frech, Oliver, Ziese | NOOP(2) Christey, Wall | Christey> Change "LIST" to "DIR" - see original post. The problem with | LIST (and NLST) occurred in Broker 3.0, not 5.0. | | The CONFIRM link is dead. | | Thanks to John Segura of secureinfo.com for noticing this. | View |
Page 1069 of 20943, showing 5 records out of 104715 total, starting on record 5341, ending on 5345