CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2914  CVE-2001-0093  Candidate  Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.  Proposed (20010202)  ACCEPT(3) Baker, Cole, Ziese | MODIFY(2) Frech, Prosser | NOOP(1) Wall | REVIEWING(1) Christey  Frech> XF:kerberos4-arbitrary-proxy(9733) | Description states FreeBSD, but advisory is for NetBSD. | Prosser> http://www.linuxsecurity.com/advisories/netbsd_advisory-1007.html | CHANGE> [Prosser changed vote from ACCEPT to MODIFY] | Prosser> The operating system in this CAN should also be NetBSD vice FreeBSD, same as in 0094. FreeBSD 3.5 STABLE and 4.2 STABLE are vulnerable as well. See ref | FreeBSD-SA-01:25 | http://www.linuxsecurity.com/advisories/freebsd_advisory-1153.html | or http://www.freebsd.org/security/security.html#adv | Christey> This description does not explicitly mention that the problem is | in a kerberized telnet. Need to verify that there aren"t | already other CVE"s that describe this.  View
2124  CVE-2000-0547  Candidate  Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.  Proposed (20000712)  ACCEPT(2) Levy, Ozancin | MODIFY(2) Cox, Frech | NOOP(2) LeBlanc, Wall  Frech> XF:kerberos-localrealm-bo(4657) | I question whether BID-1338 is appropriate here. | Cox> ADDREF REDHAT:RHSA-2000:031  View
4127  CVE-2001-1323  Candidate  Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob function.  Proposed (20020502)  ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:kerberos-inject-base64-encode(6454)  View
1276  CVE-1999-1296  Candidate  Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.  Proposed (20010912)  MODIFY(1) Frech | NOOP(2) Cole, Foat  Frech> XF:kerberos-config-file-bo(7184)  View
4001  CVE-2001-1197  Candidate  klprfax_filter in KDE2 KDEUtils allows local users to overwrite arbitrary files via a symlink attack on the klprfax.filter temporary file.  Modified (20050526)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese  Frech> XF:kdeutils-klprfax-symlink(7700)  View

Page 142 of 20943, showing 5 records out of 104715 total, starting on record 706, ending on 710

Actions