CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
346 | CVE-1999-0347 | Candidate | Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character. | Modified (20051028) | ACCEPT(4) Baker, LeBlanc, Levy, Northcutt | MODIFY(2) Frech, Prosser | REVIEWING(1) Christey | Prosser> this is a modified Cross-Frame vulnerability that circumvents | the original Cross-Frame Patch. Addressed in MS Bulletin MS99.012 | http://www.microsoft.com/security/bulletins/ms99-012.asp | Christey> Duplicate of CVE-1999-0490? | LeBlanc> If Prosser is correct that this is MS99-012, accept | Christey> BUGTRAQ:19990126 Javascript ecurity bug in Internet Explorer | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91745430007021&w=2 | NTBUGTRAQ:19990128 Javascript %01 bug in Internet Explorer | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91756771207719&w=2 | BID:197 | URL:http://www.securityfocus.com/bid/197 | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:ie-window-spoof(2069) | View |
187 | CVE-1999-0187 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | Modified (20050204) | ACCEPT(2) Hill, Northcutt | RECAST(3) Baker, Frech, Prosser | REJECT(1) Dik | REVIEWING(1) Christey | Prosser> The Sun Patches in Ref roll-up fixes for an earlier BO in | rdist lookup( )(ref CERT 96.14)as well as the BO in rdist function expstr() | (ref CERT 97-23) and various vendor bulletins. However both of these rdist | BO"s affect many more OSs than just Sun, i.e., BSD/OS 2.1, DEC OSF"s, AIX, | FreeBSD, SCO, SGI, etc. Believe this falls into the SF-codebase content | decision | Frech> XF:rdist-bo (error msg formation) | XF:rdist-bo2 (execute code) | XF:rdist-bo3 (execute user-created code) | XF:rdist-sept97 (root from local) | Christey> Duplicate of CVE-1999-0022 (SUN:00179 is referenced in | CERT:CA-97.23.rdist), but as Mike and Andre noted, there | are multiple flaws here, so a RECAST may be necessary. | Dik> As currently phrasedm thissa duplicate of CVE-1999-0022 | Baker> Based on our new philosophy, this should be recast/merged or re-described. | View |
335 | CVE-1999-0336 | Candidate | Buffer overflow in mstm in HP-UX allows local users to gain root access. | Modified (19991207-01) | ACCEPT(2) Frech, Northcutt | NOOP(3) Baker, Prosser, Shostack | RECAST(1) Christey | Prosser> same as CVE-1999-0307, only ref I can find is an old SOD | exploit on www.outpost9.com | Christey> MERGE CVE-1999-0307 (the exact exploit works with both | cstm and mstm, which are clearly part of the same package, | so CD:SF-EXEC says to merge them.) | | Also, there does not seem to be any recognition of this problem | by HP. The only other information besides the Bugtraq post | is the SOD exploit. | View |
306 | CVE-1999-0307 | Candidate | Buffer overflow in HP-UX cstm program allows local users to gain root privileges. | Modified (19991207-01) | ACCEPT(2) Frech, Northcutt | NOOP(3) Baker, Prosser, Shostack | RECAST(1) Christey | Prosser> only ref I can find is an old SOD exploit on | www.outpost9.com | Christey> MERGE CVE-1999-0336 (the exact exploit works with both | cstm and mstm, which are clearly part of the same package, | so CD:SF-EXEC says to merge them.) | | Also, there does not seem to be any recognition of this problem | by HP. The only other information besides the Bugtraq post | is the SOD exploit. | | See the original post: | http://www.securityfocus.com/templates/archive.pike?list=1&date=1996-11-15&msg=Pine.LNX.3.91.961116112242.15276J-100000@underground.org | View |
3499 | CVE-2001-0691 | Candidate | Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations. | Modified (20020817-01) | ACCEPT(6) Armstrong, Baker, Bishop, Cole, Prosser, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall | Prosser> http://www.linux-mandrake.com/en/updates/2001/MDKSA-2001-054.php3?dis=7.1 | Frech> XF:imap-ipop2d-ipop3d-bo(6269) | Christey> ADDREF RHSA-2001:094 (per Mark Cox of Red Hat) | View |
Page 18 of 20943, showing 5 records out of 104715 total, starting on record 86, ending on 90