CVE List

Id CVE No. Status Description Phase Votes Comments Actions
806  CVE-1999-0826  Entry  Buffer overflow in FreeBSD angband allows local users to gain privileges.        View
807  CVE-1999-0827  Candidate  By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.  Proposed (19991208)  ACCEPT(4) Armstrong, Baker, LeBlanc, Stracener | MODIFY(2) Cole, Frech | REVIEWING(1) Prosser  Cole> The BID is 855. If I have the right vulnerability, this allows an | attacker to access URL"s of there choosing which could lead to a compromise | of private information. | Frech> XF:http-frame-spoof | Question: Similar vulnerability to MS98-020 / CVE-1999-0869? | LeBlanc> MSRC tells me this is patched in MS00-009  View
808  CVE-1999-0828  Candidate  UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.  Modified (20000121-01)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Cole, Frech | REVIEWING(2) Christey, Prosser  Cole> This is BID 850. | Christey> See comments on CVE-1999-0988. Perhaps these two should be | merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a | loosely alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:sco-pkg-dacread-fileread  View
809  CVE-1999-0829  Candidate  HP Secure Web Console uses weak encryption.  Proposed (19991208)  ACCEPT(2) Armstrong, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Cole | REVIEWING(1) Prosser  Cole> I could not find details on this using the above references. | Frech> XF:hp-secure-console  View
810  CVE-1999-0830  Candidate  Buffer overflow in SCO UnixWare Xsco command via a long argument.  Proposed (19991208)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(3) Cole, Frech, Prosser | REVIEWING(1) Christey  Cole> This is BID 824 and the BUGTRAQ reference is 19991125. | Frech> XF:sco-unixware-xsco | Christey> Confirmed by vendor, albeit vaguely: | http://marc.theaimsgroup.com/?l=bugtraq&m=94581379905584&w=2 | | Prosser> agree with Steve on vendor confirmation, however not sure the | fix ref"d in BID 824 (SSE041) is right. It lists fixes for libnsl and | tcpip.so, nothing about xsco. SSE050b | (ftp://ftp.sco.com/SSE/security_bulletins/SB-99.26b) fixes a buffer overflow | in xsco on OpenServer (the vendor message Steve refers to) but not the | UnixWare vulnerability reported on Bugtraq and in BID824. Anyone more | familar with SCO shed some light on this? Are they the same codebase so fix | would be same? From the SCO site it seems the UnixWare and OpenSever | products are similar but have differences. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:824 | http://www.securityfocus.com/bid/824  View

Page 162 of 20943, showing 5 records out of 104715 total, starting on record 806, ending on 810

Actions