CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36873  CVE-2008-6756  Candidate  ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.  Assigned (20090427)  None (candidate not yet proposed)    View
36872  CVE-2008-6755  Candidate  ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.  Assigned (20090427)  None (candidate not yet proposed)    View
1798  CVE-2000-0220  Candidate  ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.  Proposed (20000322)  ACCEPT(1) Armstrong | MODIFY(1) Frech | NOOP(5) Baker, Cole, LeBlanc, Ozancin, Wall | REJECT(1) Blake | REVIEWING(1) Levy  Blake> Discussion on Bugtraq shows that this is a really marginal issue. Very | tough to come up with a viable attack scenario. Also, it"s part of how | this class of software works, not a flaw in the cited package. Might be | possible to recast this into something more generic.... | Frech> XF:zonealarm-exposes-info  View
28401  CVE-2007-5044  Candidate  ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreatePort and (2) NtDeleteFile kernel SSDT hooks, a partial regression of CVE-2007-2083.  Assigned (20070923)  None (candidate not yet proposed)    View
25824  CVE-2007-2467  Candidate  ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access.  Assigned (20070502)  None (candidate not yet proposed)    View

Page 14 of 20943, showing 5 records out of 104715 total, starting on record 66, ending on 70

Actions