CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1529  CVE-1999-1549  Candidate  Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user"s configuration file and execute commands.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:lynx-lynxurl-spoof(8342)  View
1481  CVE-1999-1501  Candidate  (1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REJECT(1) Christey  Frech> XF:irix-ipxchk-ipxlink-ifs-commands(7365) | Christey> DUPE CVE-1999-1040  View
3432  CVE-2001-0619  Candidate  The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The "Network Name" or SSID, which is used as a shared secret to join the network, is transmitted in the clear.  Proposed (20010727)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REJECT(1) Ziese | REVIEWING(1) Bishop  Frech> XF:orinoco-ap-plaintext-ssid(7005)  View
1031  CVE-1999-1051  Candidate  Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Frech> XF:formhandler-cgi-reply-message(7782) | Christey> I view one of these as a configuration issue: FormHandler.cgi | *could* be configured to limit hard-coded pathnames to a single | directory which, while being an information leak, would still be | "reasonably secure." But by default, it"s just not configured that | way. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are.  View
1152  CVE-1999-1172  Candidate  By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Christey> The discloser does not provide enough details to fully | understand what the problem is. This makes it difficult | because if Maximizer has a concept of "users" and it is | designed to allow any user to modify any other user"s data, | then this would not be a vulnerability or exposure, unless | that "cross-user" capability could be used to violate system | integrity, data confidentiality, or the like. There are some | features of Maximizer 6.0 that, if abused, could allow someone | to do some bad things. For example, an attacker could modify | the email addresses for contacts to redirect sales to | locations besides the customer. There"s also a capability of | assigning priorities and alarms, which could be susceptible to | an "inconvenience attack" at the very least, as well as | tie-ins to e-commerce capabilities. | | The critical question becomes: "how is this data shared" in | the first place? If it"s through a network share or other | distribution method besides transferring the complete database | between sites, then this may be accessible to any attacker who | can mimic a Maximizer client (if there is such a thing as a | client), and this could be a vulnerability or exposure | according to the CVE definition. | | However, since the Maximizer functionality is unknown to me | and not readily apparent from product documentation, it"s hard | to know what to do about this one. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:maximizer-enterprise-calendar-modification(7590)  View

Page 1124 of 20943, showing 5 records out of 104715 total, starting on record 5616, ending on 5620

Actions