CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1529 | CVE-1999-1549 | Candidate | Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user"s configuration file and execute commands. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:lynx-lynxurl-spoof(8342) | View |
1481 | CVE-1999-1501 | Candidate | (1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REJECT(1) Christey | Frech> XF:irix-ipxchk-ipxlink-ifs-commands(7365) | Christey> DUPE CVE-1999-1040 | View |
3432 | CVE-2001-0619 | Candidate | The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The "Network Name" or SSID, which is used as a shared secret to join the network, is transmitted in the clear. | Proposed (20010727) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REJECT(1) Ziese | REVIEWING(1) Bishop | Frech> XF:orinoco-ap-plaintext-ssid(7005) | View |
1031 | CVE-1999-1051 | Candidate | Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey | Frech> XF:formhandler-cgi-reply-message(7782) | Christey> I view one of these as a configuration issue: FormHandler.cgi | *could* be configured to limit hard-coded pathnames to a single | directory which, while being an information leak, would still be | "reasonably secure." But by default, it"s just not configured that | way. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are. | View |
1152 | CVE-1999-1172 | Candidate | By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey | Christey> The discloser does not provide enough details to fully | understand what the problem is. This makes it difficult | because if Maximizer has a concept of "users" and it is | designed to allow any user to modify any other user"s data, | then this would not be a vulnerability or exposure, unless | that "cross-user" capability could be used to violate system | integrity, data confidentiality, or the like. There are some | features of Maximizer 6.0 that, if abused, could allow someone | to do some bad things. For example, an attacker could modify | the email addresses for contacts to redirect sales to | locations besides the customer. There"s also a capability of | assigning priorities and alarms, which could be susceptible to | an "inconvenience attack" at the very least, as well as | tie-ins to e-commerce capabilities. | | The critical question becomes: "how is this data shared" in | the first place? If it"s through a network share or other | distribution method besides transferring the complete database | between sites, then this may be accessible to any attacker who | can mimic a Maximizer client (if there is such a thing as a | client), and this could be a vulnerability or exposure | according to the CVE definition. | | However, since the Maximizer functionality is unknown to me | and not readily apparent from product documentation, it"s hard | to know what to do about this one. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:maximizer-enterprise-calendar-modification(7590) | View |
Page 1124 of 20943, showing 5 records out of 104715 total, starting on record 5616, ending on 5620