CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8535  CVE-2004-0107  Candidate  The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.  Modified (20100819)  ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey  Frech> XF:sysstat-post-trigger-symlink(15428) | http://xforce.iss.net/xforce/xfdb/15428 | Cox> This issue is in the vendor packaging of sysstat, not sysstat itself, | and does not apply to a particular version of upstream | sysstat. Suggest "trigger scripts in various vendors packaging of | syssstat allows local users..." or "in the Red Hat packaging of sysstat" | Christey> CIAC:O-097 | URL:http://www.ciac.org/ciac/bulletins/o-097.shtml | XF:sysstat-post-trigger-symlink(15428) | URL:http://xforce.iss.net/xforce/xfdb/15428 | BID:9838 | URL:http://www.securityfocus.com/bid/9838 | Christey> FEDORA:FEDORA-2004-1372 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1372  View
8534  CVE-2004-0106  Candidate  Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.  Modified (20100819)  ACCEPT(3) Armstrong, Baker, Cox | NOOP(2) Christey, Cole | REVIEWING(1) Wall  Christey> CIAC:O-081 | URL:http://www.ciac.org/ciac/bulletins/o-081.shtml | IMMUNIX:IMNX-2004-73-002-01 | URL:http://www.securityfocus.com/advisories/6328 | BID:9655 | URL:http://www.securityfocus.com/bid/9655 | TURBO:TLSA-2004-5 | URL:http://www.turbolinux.com/security/2004/TLSA-2004-5.txt | Christey> SCO:SCOSA-2004.2 | URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2004.2/SCOSA-2004.2.txt | SCO:SCOSA-2004.3 | URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.3/SCOSA-2004.3.txt  View
8533  CVE-2004-0105  Candidate  Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.  Modified (20050808)  ACCEPT(5) Armstrong, Baker, Cole, Cox, Wall    View
8532  CVE-2004-0104  Candidate  Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.  Modified (20050808)  ACCEPT(5) Armstrong, Baker, Cole, Cox, Wall    View
8531  CVE-2004-0103  Candidate  crawl before 4.0.0 beta23 does not properly "apply a size check" when copying a certain environment variable, which may allow local users to gain privileges, possibly as a result of a buffer overflow.  Modified (20050808)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(2) Cox, Wall    View

Page 19237 of 20943, showing 5 records out of 104715 total, starting on record 96181, ending on 96185

Actions