CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2780  CVE-2000-1213  Candidate  ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping"s exposure to bugs that otherwise would occur at lower privileges.  Proposed (20020830)  ACCEPT(7) Armstrong, Baker, Cole, Cox, Foat, Green, Wall | MODIFY(1) Frech  Frech> XF:iputils-ping-privileges(11090)  View
4187  CVE-2001-1384  Candidate  ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp.  Proposed (20020830)  ACCEPT(7) Armstrong, Baker, Cole, Cox, Frech, Green, Wall | NOOP(1) Foat    View
3924  CVE-2001-1120  Candidate  Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates.  Modified (20040811)  ACCEPT(7) Armstrong, Baker, Cole, Foat, Frech, Green, Ziese | NOOP(1) Christey | REVIEWING(1) Wall  Green> Acknowledged by vendor in Macromedia Product Security Bulletin (MPSB01-07) issued in July, 2001 | Foat> Note that the link to the confirm should be | http://www.macomedia.com/v1/handlers/index.cfm?id=21566. | Christey> Add period to the end of the description.  View
3929  CVE-2001-1125  Candidate  Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.  Proposed (20020315)  ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall  Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split  View
3930  CVE-2001-1126  Candidate  Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.  Proposed (20020315)  ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall  Green> IN ONE VERSION, BUT NOT IN THE OTHER | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Concur with Analysis, this should be split. The DoS would | include all versions of LiveUpdate, 1.4.x through 1.6.x. The | potential for unauthorized code execution only impacts 1.4.x through | 1.5.x.  View

Page 1092 of 20943, showing 5 records out of 104715 total, starting on record 5456, ending on 5460

Actions