CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7496  CVE-2003-0669  Candidate  Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.  Assigned (20030807)  None (candidate not yet proposed)    View
7497  CVE-2003-0670  Candidate  Sustworks IPNetSentryX and IPNetMonitorX allow local users to sniff network packets via the setuid helper applications (1) RunTCPDump, which calls tcpdump, and (2) RunTCPFlow, which calls tcpflow.  Assigned (20030807)  None (candidate not yet proposed)    View
7498  CVE-2003-0671  Candidate  Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.  Assigned (20030807)  None (candidate not yet proposed)    View
7499  CVE-2003-0672  Candidate  Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.  Assigned (20030807)  None (candidate not yet proposed)    View
7500  CVE-2003-0676  Candidate  Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.  Assigned (20030808)  None (candidate not yet proposed)    View

Page 1500 of 20943, showing 5 records out of 104715 total, starting on record 7496, ending on 7500

Actions