CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1393  CVE-1999-1413  Candidate  Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.  Proposed (20010912)  MODIFY(2) Dik, Frech | NOOP(2) Cole, Foat  Frech> XF:solaris-coredump-symlink(7196) | Dik> sun bug: 1208241 | | Also applies to set-uid executables that have made real | and effective uid identical  View
852  CVE-1999-0872  Candidate  Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.  Proposed (19991214)  MODIFY(2) Cole, Frech | NOOP(1) Baker | REJECT(3) Blake, Christey, Stracener  Cole> 611 is the mail to listed above but 759 is for the mail from and | should be listed as a separate vulenrability. | Blake> This does not appear materially different from CVE-1999-0768 | Christey> This is an apparent duplicate of CVE-1999-0768. | REDHAT:RHSA-1999:030-02 describes two issues, one of which is | CVE-1999-0768, and the other is CVE-1999-0769. | Stracener> This is a duplicate of candidate CVE-1999-0768. | Frech> XF:cron-sendmail-bo-root | Christey> BID:759 is improperly assigned to this candidate and doesn"t | even describe it. It may have been inadvertently copied | from CVE-1999-0873.  View
3569  CVE-2001-0762  Candidate  Buffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument.  Proposed (20011012)  MODIFY(2) Christey, Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:suid-wrapper-argument-bo(6675) | Christey> Add "suid wrapper" to desc. | ADDREF BID:2837 | URL:http://www.securityfocus.com/bid/2837  View
1655  CVE-2000-0077  Candidate  The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.  Modified (20090302)  MODIFY(2) Baker, Frech | REVIEWING(1) Christey  Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is October 1998 equivalent to HP-UX 10.x? | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0078. | Baker> Was the BID reference ever added to this one?  View
570  CVE-1999-0588  Candidate  A filter in a router or firewall allows unusual fragmented packets.  Proposed (19990726)  MODIFY(2) Baker, Frech | REJECT(1) Northcutt  Northcutt> I want to vote to accept this one, but unusual is a shade broad. | Frech> XF:nt-rras | XF:cisco-fragmented-attacks | XF:ip-frag | Baker> Perhaps we should use the word abnormally fragmented or some other descriptor.  View

Page 19786 of 20943, showing 5 records out of 104715 total, starting on record 98926, ending on 98930

Actions