CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
114 | CVE-1999-0114 | Candidate | Local users can execute commands as other users, and read other users" files, through the filter command in the Elm elm-2.4 mail package using a symlink attack. | Modified (20000106-01) | ACCEPT(7) Armstrong, Bishop, Blake, Cole, Landfield, Shostack, Wall | MODIFY(2) Baker, Frech | NOOP(3) Christey, Northcutt, Ozancin | REVIEWING(1) Levy | Frech> XF:elm-filter2 | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Landfield> with Frech modifications | Baker> ADD REF http://www.cert.org/ftp/cert_bulletins/VB-95:10a.elm Official Advisory | Christey> The correct URL is http://www.cert.org/vendor_bulletins/VB-95:10a.elm | Need to make sure that this CERT advisory describes the right | problem, especially since the CERT advisory is dated December | 18, 1995 and the original Bugtraq post was December 26, 1995. | Christey> BID:1802 | URL:http://www.securityfocus.com/bid/1802 | BID:1802 doesn"t include the 1999 posting - does Security | Focus think that the 1999 post describes a different | vulnerability? | Christey> XF:elm-filter2 isn"t on the X-Force web site. How about XF:elm-filter(402) ? | Its references point to the December 26, 1995 BUgtraq post. | | Also consider CIAC:G-36 and CERT:VB-95:10 | Frech> DELREF:XF:elm-filter2(711) | ADDREF:XF:elm-filter(402) | View |
1314 | CVE-1999-1334 | Candidate | Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument. | Proposed (20010912) | ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(2) Armstrong, Wall | Frech> XF:elm-filter-getfilterrules-bo(7214) | XF:elm-filter2(711) | View |
3914 | CVE-2001-1110 | Candidate | EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection. | Proposed (20020315) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese | Frech> XF:eftp-list-directory-traversal(7113) | In description, NETBIOS should be NetBIOS. | View |
2414 | CVE-2000-0845 | Candidate | kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet. | Proposed (20001018) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall | Frech> XF:du-kdebugd-write-access(5262) | Christey> This problem also allows attackers to overwrite files. | ADDREF BID:1693 | ADDREF URL:http://www.securityfocus.com/bid/1693 | ADDREF XF:du-kdebugd-write-access | ADDREF http://xforce.iss.net/static/5262.php | View |
1357 | CVE-1999-1377 | Candidate | Matt Wright"s download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:download-cgi-directory-traversal(8279) | View |
Page 183 of 20943, showing 5 records out of 104715 total, starting on record 911, ending on 915