CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1393 | CVE-1999-1413 | Candidate | Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg. | Proposed (20010912) | MODIFY(2) Dik, Frech | NOOP(2) Cole, Foat | Frech> XF:solaris-coredump-symlink(7196) | Dik> sun bug: 1208241 | | Also applies to set-uid executables that have made real | and effective uid identical | View |
852 | CVE-1999-0872 | Candidate | Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. | Proposed (19991214) | MODIFY(2) Cole, Frech | NOOP(1) Baker | REJECT(3) Blake, Christey, Stracener | Cole> 611 is the mail to listed above but 759 is for the mail from and | should be listed as a separate vulenrability. | Blake> This does not appear materially different from CVE-1999-0768 | Christey> This is an apparent duplicate of CVE-1999-0768. | REDHAT:RHSA-1999:030-02 describes two issues, one of which is | CVE-1999-0768, and the other is CVE-1999-0769. | Stracener> This is a duplicate of candidate CVE-1999-0768. | Frech> XF:cron-sendmail-bo-root | Christey> BID:759 is improperly assigned to this candidate and doesn"t | even describe it. It may have been inadvertently copied | from CVE-1999-0873. | View |
3569 | CVE-2001-0762 | Candidate | Buffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument. | Proposed (20011012) | MODIFY(2) Christey, Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> XF:suid-wrapper-argument-bo(6675) | Christey> Add "suid wrapper" to desc. | ADDREF BID:2837 | URL:http://www.securityfocus.com/bid/2837 | View |
1655 | CVE-2000-0077 | Candidate | The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands. | Modified (20090302) | MODIFY(2) Baker, Frech | REVIEWING(1) Christey | Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is October 1998 equivalent to HP-UX 10.x? | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0078. | Baker> Was the BID reference ever added to this one? | View |
570 | CVE-1999-0588 | Candidate | A filter in a router or firewall allows unusual fragmented packets. | Proposed (19990726) | MODIFY(2) Baker, Frech | REJECT(1) Northcutt | Northcutt> I want to vote to accept this one, but unusual is a shade broad. | Frech> XF:nt-rras | XF:cisco-fragmented-attacks | XF:ip-frag | Baker> Perhaps we should use the word abnormally fragmented or some other descriptor. | View |
Page 19786 of 20943, showing 5 records out of 104715 total, starting on record 98926, ending on 98930