CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2953 | CVE-2001-0132 | Candidate | Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack. | Proposed (20010214) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:interscan-viruswall-symlink | URL:http://xforce.iss.net/static/5947.php | Frech> XF:interscan-viruswall-symlink(5947) | View |
2956 | CVE-2001-0135 | Candidate | The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs. | Proposed (20010214) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:ultraboard-cgi-perm | URL:http://xforce.iss.net/static/5931.php | Frech> XF:ultraboard-cgi-perm(5931) | In description, "writeable": from | http://www.dictionary.com/cgi-bin/dict.pl?term=Writable: Writable | Writ"a*ble, a. Capable of, or suitable for, being written down. | Christey> Yeah yeah yeah, Andre, I knew you"d catch my bad spelling :-) | View |
1075 | CVE-1999-1095 | Candidate | sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Foat | Frech> XF:sort-tmp-file-symlink(7182) | Christey> This issue clearly has a long history. | CALDERA:CSSA-2002-SCO.21 | URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0018.html | CALDERA:CSSA-2002-SCO.2 | URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q1/0002.html | (There are 2 Caldera advisories because one is for Open UNIX | and UnixWare, and the other is for OpenServer) | | XF:openserver-sort-symlink(9218) | URL:http://www.iss.net/security_center/static/9218.php | View |
1388 | CVE-1999-1408 | Candidate | Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Foat | Frech> XF: aix-hpux-connect-dos(7195) | Christey> BUGTRAQ:19970307 Re: Bug in connect() ? | URL:http://www.securityfocus.com/archive/1/Pine.HPP.3.92.970307195408.12139B-100000@wpax13.physik.uni-wuerzburg.de | BUGTRAQ:19970311 Re: Bug in connect() for aix 4.1.4 ? | URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=6419 | View |
1864 | CVE-2000-0286 | Candidate | X fontserver xfs allows local users to cause a denial of service via malformed input to the server. | Proposed (20000426) | MODIFY(1) Frech | NOOP(3) Baker, Cole, Wall | REJECT(2) Christey, Levy | Frech> XF:redhat-fontserver-dos | POTENTIAL DUPE: CVE-2000-0263: The X font server xfs in Red Hat Linux 6.x | allows an attacker to cause a denial of service via a malformed request. | Christey> As Andre observed, this is a duplicate of CVE-2000-0263. | View |
Page 19838 of 20943, showing 5 records out of 104715 total, starting on record 99186, ending on 99190