CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1943  CVE-2000-0365  Candidate  Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.  Proposed (20000524)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:linux-dev-insecure-mode | Christey> BUGTRAQ:19990607 Re: RedHat 6.0, /dev/pts permissions bug when using xterm | http://marc.theaimsgroup.com/?l=bugtraq&m=92886008912147&w=2 | BUGTRAQ:19990607 Re: Red Hat 6.0, /dev/pts permissions bug when using xterm | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92886358415964&w=2  View
2701  CVE-2000-1134  Candidate  Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.  Modified (20061101)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> XF:linux-bash-tmp-symlink(5593) | Christey> Don"t all these shell programs originate from the same | codebase, including ksh? If so, we should have a single CAN | for all of these, and add: | XF:ksh-redirection-symlink | URL:http://xforce.iss.net/static/5811.php | CONECTIVA:CLA-2000:354 | BUGTRAQ:20001208 Immunix OS Security update for tcsh | http://archives.neohapsis.com/archives/linux/immunix/2000-q4/0041.html | BUGTRAQ:20001220 /bin/ksh creates insecure tmp files | http://archives.neohapsis.com/archives/bugtraq/2000-12/0368.html | BUGTRAQ:20001227 IBM Findings: Korn Shell Redirection Race Condition Vulnerability | http://archives.neohapsis.com/archives/bugtraq/2000-12/0473.html | | Also see: http://archives.neohapsis.com/archives/bugtraq/2000-12/0420.html | which gives some shell history which may be of use. | Christey> ADDREF FREEBSD:FreeBSD-SA-01:03 for the bash problem. | Christey> Consider adding BID:2148 if this CAN should include ksh | Christey> SGI:20011103-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/20011103-01-I | Also, DELREF BID:2148 and BID:1926. Keep BID:2006 | Christey> COMPAQ:SSRT1-41U | URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0742U-59U.shtml | CERT-VN:VU#10277 | URL:http://www.kb.cert.org/vuls/id/10277 | Christey> SGI:20011103-02-P | URL:ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P | Note that this is an update of the other SGI reference. | Christey> CALDERA:CSSA-2001-SCO.24 | URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.24.1/CSSA-2001-SCO.24.1.txt | CERT-VN:VU#10277 | URL:http://www.kb.cert.org/vuls/id/10277 | Christey> Missing BID - BID:1926 | Christey> HP:SSRT3618 | URL:http://archives.neohapsis.com/archives/hp/2003-q3/0042.html  View
2952  CVE-2001-0131  Candidate  htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.  Modified (20010430-01)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Magdych, Wall  Frech> XF:linux-apache-symlink(5926) | Christey> XF:linux-apache-symlink | URL:http://xforce.iss.net/static/5926.php | Christey> http://archives.neohapsis.com/archives/vendor/2001-q1/0019.html | Christey> This item may have been re-introduced into the Apache source | code sometime during 2002; CVE-2002-1233 has been created for | that version, which affects Apache 1.3.27 and other versions. | Christey> As a further clarification, CVE-2002-1233 is *only* for the | Debian-specific regression error. | Christey> DEBIAN:DSA-195 | URL:http://www.debian.org/security/2002/dsa-195  View
3213  CVE-2001-0395  Candidate  Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:lightwave-consoleserver-brute-force(6345)  View
3214  CVE-2001-0396  Candidate  The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:lightwave-consoleserver-brute-force(6345)  View

Page 140 of 20943, showing 5 records out of 104715 total, starting on record 696, ending on 700

Actions