CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3683  CVE-2001-0877  Entry  Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic (e.g., chargen), or (2) via a spoofed SSDP announcement to broadcast or multicast addresses, which could cause all UPnP clients to send traffic to a single target system.        View
1071  CVE-1999-1091  Candidate  UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(2) Cole, Foat    View
922  CVE-1999-0942  Entry  UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.        View
1607  CVE-2000-0029  Entry  UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.        View
808  CVE-1999-0828  Candidate  UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.  Modified (20000121-01)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Cole, Frech | REVIEWING(2) Christey, Prosser  Cole> This is BID 850. | Christey> See comments on CVE-1999-0988. Perhaps these two should be | merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a | loosely alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:sco-pkg-dacread-fileread  View

Page 18626 of 20943, showing 5 records out of 104715 total, starting on record 93126, ending on 93130

Actions