CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2582  CVE-2000-1013  Candidate  The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.  Proposed (20001129)  ACCEPT(2) Cole, Mell | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:freebsd-display-read-files(5645)  View
2328  CVE-2000-0752  Candidate  Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.  Proposed (20000921)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:freebsd-brouted-bo(6185)  View
1031  CVE-1999-1051  Candidate  Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Frech> XF:formhandler-cgi-reply-message(7782) | Christey> I view one of these as a configuration issue: FormHandler.cgi | *could* be configured to limit hard-coded pathnames to a single | directory which, while being an information leak, would still be | "reasonably secure." But by default, it"s just not configured that | way. | | My brain hurts too much right now. There are a couple | problems with the references and descriptions of CVE-1999-1050 | and CVE-1999-1051. I"m interpreting the underlying nature | of the problem(s) a little differently than others are. | Some of it may be due to differing definitions or thoughts | about what "directory traversal vulnerabilities" are.  View
2700  CVE-2000-1133  Candidate  Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.  Proposed (20001219)  MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:flicks-authentix-url-info(5477)  View
2297  CVE-2000-0721  Candidate  The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.  Proposed (20000921)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:flagship-incorrect-permissions(5114)  View

Page 177 of 20943, showing 5 records out of 104715 total, starting on record 881, ending on 885

Actions