CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2953  CVE-2001-0132  Candidate  Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.  Proposed (20010214)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:interscan-viruswall-symlink | URL:http://xforce.iss.net/static/5947.php | Frech> XF:interscan-viruswall-symlink(5947)  View
2956  CVE-2001-0135  Candidate  The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.  Proposed (20010214)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall  Christey> XF:ultraboard-cgi-perm | URL:http://xforce.iss.net/static/5931.php | Frech> XF:ultraboard-cgi-perm(5931) | In description, "writeable": from | http://www.dictionary.com/cgi-bin/dict.pl?term=Writable: Writable | Writ"a*ble, a. Capable of, or suitable for, being written down. | Christey> Yeah yeah yeah, Andre, I knew you"d catch my bad spelling :-)  View
1075  CVE-1999-1095  Candidate  sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Foat  Frech> XF:sort-tmp-file-symlink(7182) | Christey> This issue clearly has a long history. | CALDERA:CSSA-2002-SCO.21 | URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0018.html | CALDERA:CSSA-2002-SCO.2 | URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q1/0002.html | (There are 2 Caldera advisories because one is for Open UNIX | and UnixWare, and the other is for OpenServer) | | XF:openserver-sort-symlink(9218) | URL:http://www.iss.net/security_center/static/9218.php  View
1388  CVE-1999-1408  Candidate  Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Foat  Frech> XF: aix-hpux-connect-dos(7195) | Christey> BUGTRAQ:19970307 Re: Bug in connect() ? | URL:http://www.securityfocus.com/archive/1/Pine.HPP.3.92.970307195408.12139B-100000@wpax13.physik.uni-wuerzburg.de | BUGTRAQ:19970311 Re: Bug in connect() for aix 4.1.4 ? | URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=6419  View
1864  CVE-2000-0286  Candidate  X fontserver xfs allows local users to cause a denial of service via malformed input to the server.  Proposed (20000426)  MODIFY(1) Frech | NOOP(3) Baker, Cole, Wall | REJECT(2) Christey, Levy  Frech> XF:redhat-fontserver-dos | POTENTIAL DUPE: CVE-2000-0263: The X font server xfs in Red Hat Linux 6.x | allows an attacker to cause a denial of service via a malformed request. | Christey> As Andre observed, this is a duplicate of CVE-2000-0263.  View

Page 19838 of 20943, showing 5 records out of 104715 total, starting on record 99186, ending on 99190

Actions