CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2914 | CVE-2001-0093 | Candidate | Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd. | Proposed (20010202) | ACCEPT(3) Baker, Cole, Ziese | MODIFY(2) Frech, Prosser | NOOP(1) Wall | REVIEWING(1) Christey | Frech> XF:kerberos4-arbitrary-proxy(9733) | Description states FreeBSD, but advisory is for NetBSD. | Prosser> http://www.linuxsecurity.com/advisories/netbsd_advisory-1007.html | CHANGE> [Prosser changed vote from ACCEPT to MODIFY] | Prosser> The operating system in this CAN should also be NetBSD vice FreeBSD, same as in 0094. FreeBSD 3.5 STABLE and 4.2 STABLE are vulnerable as well. See ref | FreeBSD-SA-01:25 | http://www.linuxsecurity.com/advisories/freebsd_advisory-1153.html | or http://www.freebsd.org/security/security.html#adv | Christey> This description does not explicitly mention that the problem is | in a kerberized telnet. Need to verify that there aren"t | already other CVE"s that describe this. | View |
2124 | CVE-2000-0547 | Candidate | Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(2) Cox, Frech | NOOP(2) LeBlanc, Wall | Frech> XF:kerberos-localrealm-bo(4657) | I question whether BID-1338 is appropriate here. | Cox> ADDREF REDHAT:RHSA-2000:031 | View |
4127 | CVE-2001-1323 | Candidate | Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob function. | Proposed (20020502) | ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:kerberos-inject-base64-encode(6454) | View |
1276 | CVE-1999-1296 | Candidate | Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable. | Proposed (20010912) | MODIFY(1) Frech | NOOP(2) Cole, Foat | Frech> XF:kerberos-config-file-bo(7184) | View |
4001 | CVE-2001-1197 | Candidate | klprfax_filter in KDE2 KDEUtils allows local users to overwrite arbitrary files via a symlink attack on the klprfax.filter temporary file. | Modified (20050526) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | Frech> XF:kdeutils-klprfax-symlink(7700) | View |
Page 142 of 20943, showing 5 records out of 104715 total, starting on record 706, ending on 710