CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4499  CVE-2002-0105  Candidate  CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey  Christey> CALDERA:CSSA-2002-SCO.18 | XF:cde-dt-world-writable(9045) | URL:http://www.iss.net/security_center/static/9045.php | Note: the advisory sort-of implies that world-write | permissions were the key problem, so the fact that a symlink | attack could take place did not necessarily mean that a | symlink following vulnerability really existed, in the sense | that symlink attacks don"t exist in directories that are | not writable by other users (well, without those users | exploiting some *other* vulnerability to allow them to create | the symlink!) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Hmmm... should XF:cde-dt-world-writable(9045) really be added | here? ISS may have "split" between the permissions issue | and the symlink problem.  View
3988  CVE-2001-1184  Candidate  wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024.  Proposed (20020315)  ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall    View
4500  CVE-2002-0106  Candidate  BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
3991  CVE-2001-1187  Candidate  csvform.pl 0.1 allows remote attackers to execute arbitrary commands via metacharacters in the file parameter.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4503  CVE-2002-0109  Candidate  Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.  Proposed (20020315)  ACCEPT(2) Frech, Green | MODIFY(1) Foat | NOOP(2) Cole, Wall  Foat> Our testing showed that this vulnerabiltiy did not apply to BEFSR41 | routers.  View

Page 166 of 20943, showing 5 records out of 104715 total, starting on record 826, ending on 830

Actions