CVE List

Id CVE No. Status Description Phase Votes Comments Actions
114  CVE-1999-0114  Candidate  Local users can execute commands as other users, and read other users" files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.  Modified (20000106-01)  ACCEPT(7) Armstrong, Bishop, Blake, Cole, Landfield, Shostack, Wall | MODIFY(2) Baker, Frech | NOOP(3) Christey, Northcutt, Ozancin | REVIEWING(1) Levy  Frech> XF:elm-filter2 | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Landfield> with Frech modifications | Baker> ADD REF http://www.cert.org/ftp/cert_bulletins/VB-95:10a.elm Official Advisory | Christey> The correct URL is http://www.cert.org/vendor_bulletins/VB-95:10a.elm | Need to make sure that this CERT advisory describes the right | problem, especially since the CERT advisory is dated December | 18, 1995 and the original Bugtraq post was December 26, 1995. | Christey> BID:1802 | URL:http://www.securityfocus.com/bid/1802 | BID:1802 doesn"t include the 1999 posting - does Security | Focus think that the 1999 post describes a different | vulnerability? | Christey> XF:elm-filter2 isn"t on the X-Force web site. How about XF:elm-filter(402) ? | Its references point to the December 26, 1995 BUgtraq post. | | Also consider CIAC:G-36 and CERT:VB-95:10 | Frech> DELREF:XF:elm-filter2(711) | ADDREF:XF:elm-filter(402)  View
1314  CVE-1999-1334  Candidate  Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.  Proposed (20010912)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(2) Armstrong, Wall  Frech> XF:elm-filter-getfilterrules-bo(7214) | XF:elm-filter2(711)  View
3914  CVE-2001-1110  Candidate  EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.  Proposed (20020315)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese  Frech> XF:eftp-list-directory-traversal(7113) | In description, NETBIOS should be NetBIOS.  View
2414  CVE-2000-0845  Candidate  kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.  Proposed (20001018)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Armstrong, Christey, Cole, Magdych, Wall  Frech> XF:du-kdebugd-write-access(5262) | Christey> This problem also allows attackers to overwrite files. | ADDREF BID:1693 | ADDREF URL:http://www.securityfocus.com/bid/1693 | ADDREF XF:du-kdebugd-write-access | ADDREF http://xforce.iss.net/static/5262.php  View
1357  CVE-1999-1377  Candidate  Matt Wright"s download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:download-cgi-directory-traversal(8279)  View

Page 183 of 20943, showing 5 records out of 104715 total, starting on record 911, ending on 915

Actions