CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3021 | CVE-2001-0200 | Candidate | HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled. | Proposed (20010309) | ACCEPT(1) Lawler | MODIFY(1) Frech | NOOP(1) Ziese | Frech> XF:hsweb-directory-browsing(6061) | View |
3986 | CVE-2001-1182 | Candidate | Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges. | Modified (20090302) | ACCEPT(5) Armstrong, Baker, Cole, Green, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey | Frech> XF:hpux-login-unauthorized-access(6860) | Christey> CIAC:L-114 | URL:http://ciac.llnl.gov/ciac/bulletins/l-114.shtml | BID:3068 | URL:http://online.securityfocus.com/bid/3068 | | This would appear to be a dupe of CVE-2001-0797, but the HP advisory | from CVE-2001-0797 is too vague to be certain. As quoted in | the CERT advisory for CVE-2001-0797, HP says: | "HP-UX does have a benign buffer overflow... [which] has been | fixed by HP." HP:HPSBUX0107-160 (CVE-2001-1182) states that | "The login(1) command allows restricted shell users to | circumvent security checks" which could be interpreted as | meaning that HP has found a slightly less-than-benign aspect | of the overflow, but since (a) the advisory says nothing about | overflows and (b) the advisory does not include any | cross-references, it cannot be clear. There is a difference | in the release dates as well, however, since the HP advisory | was released in July 2001 and this CAN was publicized in | December 2001, which may be sufficient evidence that the | problems are different. | | This probably is not the same issue in login as CVE-2001-0978, | since different patches are referenced in that CAN. | | There is insufficient information to know whether this is the | same issue as CVE-2001-0094 (kerberos library issues that | affect kerberized login). | View |
2693 | CVE-2000-1126 | Candidate | Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service. | Modified (20090302) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:hpux-autoparms-execute-commands(5961) | View |
1114 | CVE-1999-1134 | Candidate | Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066. | Modified (20020217-01) | ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | Frech> XF:hp-vue(2284) | Packetstorm URL is dead. Try another archive. | View |
3419 | CVE-2001-0606 | Candidate | Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service. | Modified (20020225-01) | ACCEPT(6) Baker, Bishop, Cole, Wall, Williams, Ziese | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:hp-virtualvault-iws-dos(6110) | CHANGE> [Williams changed vote from REVIEWING to ACCEPT] | View |
Page 166 of 20943, showing 5 records out of 104715 total, starting on record 826, ending on 830