CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5275 | CVE-2002-0885 | Candidate | Multiple buffer overflows in in.rarpd (ARP server) on Solaris, and possibly other operating systems including Caldera UnixWare and Open UNIX, allow remote attackers to execute arbitrary code, possibly via the functions (1) syserr and (2) error. | Proposed (20020830) | ACCEPT(3) Baker, Cole, Frech | MODIFY(1) Alderson | NOOP(5) Armstrong, Christey, Cox, Foat, Jones | Jones> Need clarification/verification. | Alderson> Personally, since this one is not only vague, but extremely vague | and not even confirmed, I believe it should be lumped with the previous one | that has been confirmed and is much less vague. | Christey> Correction: this is a RARP (Reverse Address Resolution | Protocol) server. | A colleague of mine with access to Solaris source has noted | that the affected syslog calls can not be fed user-supplied | data, at least for Solaris; if so, then this is not a vulnerability. | View |
2458 | CVE-2000-0889 | Candidate | Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun. | Proposed (20010202) | ACCEPT(3) Baker, Cole, Dik | MODIFY(1) Frech | NOOP(2) Wall, Ziese | REVIEWING(1) Christey | Frech> XF:sun-compromised-certificate(5404) | Christey> Should revoked cert"s be included in CVE? How about the ones | for Microsoft from early 2001? | View |
2723 | CVE-2000-1156 | Candidate | StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice. | Modified (20010116-01) | ACCEPT(3) Baker, Cole, Dik | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> XF:staroffice-tmp-sym-link(5487) | Christey> Consult Sun on this one. | Dik> Supposedly fixed in Soffice 5.1 Service pack 1 | View |
5477 | CVE-2002-1090 | Candidate | Buffer overflow in read_smtp_response of protocol.c in libesmtp before 0.8.11 allows a remote SMTP server to (1) execute arbitrary code via a certain response or (2) cause a denial of service via long server responses. | Proposed (20030317) | ACCEPT(3) Baker, Cole, Cox | NOOP(2) Christey, Wall | Christey> REDHAT:RHSA-2003:109 | URL:http://www.redhat.com/support/errata/RHSA-2003-109.html | Christey> CONECTIVA:CLA-2003:630 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000630 | View |
4984 | CVE-2002-0593 | Candidate | Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI. | Modified (20071113) | ACCEPT(3) Baker, Cole, Cox | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:mozilla-netscape-irc-bo(8976) | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | View |
Page 20020 of 20943, showing 5 records out of 104715 total, starting on record 100096, ending on 100100