CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2780 | CVE-2000-1213 | Candidate | ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping"s exposure to bugs that otherwise would occur at lower privileges. | Proposed (20020830) | ACCEPT(7) Armstrong, Baker, Cole, Cox, Foat, Green, Wall | MODIFY(1) Frech | Frech> XF:iputils-ping-privileges(11090) | View |
4187 | CVE-2001-1384 | Candidate | ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp. | Proposed (20020830) | ACCEPT(7) Armstrong, Baker, Cole, Cox, Frech, Green, Wall | NOOP(1) Foat | View | |
3924 | CVE-2001-1120 | Candidate | Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates. | Modified (20040811) | ACCEPT(7) Armstrong, Baker, Cole, Foat, Frech, Green, Ziese | NOOP(1) Christey | REVIEWING(1) Wall | Green> Acknowledged by vendor in Macromedia Product Security Bulletin (MPSB01-07) issued in July, 2001 | Foat> Note that the link to the confirm should be | http://www.macomedia.com/v1/handlers/index.cfm?id=21566. | Christey> Add period to the end of the description. | View |
3929 | CVE-2001-1125 | Candidate | Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site. | Proposed (20020315) | ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split | View |
3930 | CVE-2001-1126 | Candidate | Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. | Proposed (20020315) | ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall | Green> IN ONE VERSION, BUT NOT IN THE OTHER | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Concur with Analysis, this should be split. The DoS would | include all versions of LiveUpdate, 1.4.x through 1.6.x. The | potential for unauthorized code execution only impacts 1.4.x through | 1.5.x. | View |
Page 1092 of 20943, showing 5 records out of 104715 total, starting on record 5456, ending on 5460