CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2027 | CVE-2000-0449 | Candidate | Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields. | Proposed (20000615) | ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:omnis-studio-weak-encryption | View |
4686 | CVE-2002-0294 | Candidate | Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Frech> XF:omnipcx-shutdown-permissions(8226) | REASON: LIKELY | Christey> Acknowledged by Alcatel via email October 4, 2002 | View |
4687 | CVE-2002-0295 | Candidate | Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Frech> XF:omnipcx-insecure-groups(8227) | REASON: LIKELY | Christey> Acknowledged by Alcatel via email October 4, 2002 | View |
4685 | CVE-2002-0293 | Candidate | FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root"s .profile file. | Modified (20050527) | MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall | Frech> XF:omnipcx-ftp-root-access(8225) | Christey> Acknowledged by Alcatel via email October 4, 2002 | View |
950 | CVE-1999-0970 | Candidate | The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created. | Modified (20020226-01) | ACCEPT(3) Baker, Blake, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy | Frech> XF:omnihttpd-dos | Christey> Some sort of confirmation might be findable at: | http://www.omnicron.ab.ca/httpd/docs/release.html | Christey> See http://www.omnicron.ab.ca/index.html | The August 16, 2000 news item says "This release fixes some | security problems." It"s for version 2.07, but the discloser | didn"t say what version was available. | | Other security fixes are in the release notes at | http://www.omnicron.ab.ca/httpd/docs/release.html Notes for | Professional Version 1.01 say "Patched up two security weaknesses." | Notes for version 2.07 say "Fixes dot-appending vulnerability." | Professional Alpha 7 says "Revamped CGI launching and security," | Professional Alpha 4 says "Fixed SSI path mapping and security | problems," Alpha 5 says "Security fixup." | | In other words, you can"t tell whether they"ve fixed this bug | or not. | Christey> BID:1808 | URL:http://www.securityfocus.com/bid/1808 | View |
Page 119 of 20943, showing 5 records out of 104715 total, starting on record 591, ending on 595