CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4133  CVE-2001-1329  Candidate  Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root priveleges via a long command line argument.  Proposed (20020502)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | REJECT(1) Christey  Christey> Acknowledged by vendor (Troy Bollinger no less ;-) in: | BUGTRAQ:20010612 Re: (forw) rsh bufferoverflow on AIX 4.2 | URL:http://online.securityfocus.com/archive/1/190630 | | HOWEVER... this looks like a rediscovery of CVE-1999-0101. | Troy"s June 2001 response mentions a gethostbyname() problem | in 1996, which is CVE-1999-0101. | Frech> XF:dns-leng-ovf(637) | XF:ghbn-bo(1751) | Also assigned: CVE-1999-0101 | In description, "privileges" is misspelled.  View
4645  CVE-2002-0253  Candidate  PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.  Proposed (20020502)  ACCEPT(1) Frech | NOOP(6) Armstrong, Christey, Cole, Cox, Foat, Wall  Christey> Is this another case when PHP leaks path information by design, | as supported by "display_errors" option? Then the | vulnerability (rather, exposure) would be in the use of the | display_errors option itself, whose implications may include | this particular scenario. | CHANGE> [Cox changed vote from REVIEWING to NOOP]  View
4134  CVE-2001-1330  Candidate  Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.  Proposed (20020502)  ACCEPT(1) Green | NOOP(4) Cole, Cox, Foat, Wall | REJECT(2) Christey, Frech  Christey> Reject this for 2 reasons: | (1) It"s a carbon copy of CVE-2001-1329 | (2) CVE-2001-1329 is a dupe of CVE-1999-0101, which means | CVE-2001-1330 is, too. | Frech> CVE-2001-1330 is the same as CVE-2001-1329  View
4646  CVE-2002-0254  Candidate  ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains large height and width values, which causes the crash when viewed in Userdetails.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall  Frech> XF:icq-large-jpg-bo(8159)  View
4135  CVE-2001-1331  Candidate  mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mandb-tmpfile-symlink(9989)  View

Page 127 of 20943, showing 5 records out of 104715 total, starting on record 631, ending on 635

Actions