CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1890  CVE-2000-0312  Candidate  cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron"s fake popen function.  Proposed (20010214)  ACCEPT(3) Baker, Cole, Collins | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> XF:cron-sendmail-root(3335) | Seems like this issue is not just OpenBSD, and is described | differently by other vendors: | SuSE Security Announcement #15 Security hole in cron | http://www.suse.de/de/support/security/suse_security_announce_15.txt | Red Hat, Inc. Security Advisory RHSA-1999:030-02 Buffer overflow in | cron daemon | http://www.redhat.com/support/errata/rh52-errata-general.html#vixie-cron | Caldera Systems, Inc. Security Advisory CSSA-1999-023.0 serious security | problem in cron | http://www.calderasystems.com/support/security/advisories/CSSA-1999-023.0.tx | t | All are dated on or around 1999-08-27 to 1999-08-30. | Also, may overlap with CVE-1999-0769: Vixie Cron on Linux systems allows | local users to set parameters of sendmail commands via the MAILTO | environmental variable. | Christey> See Andre"s comments, but I believe this is different than | CVE-1999-0769. Also consider CVE-1999-0768 and CVE-1999-0872 | (Vixie Cron buffer overflow via MAILTO),  View
5132  CVE-2002-0742  Candidate  Buffer overflow in pioout on AIX 4.3.3.  Proposed (20020726)  ACCEPT(3) Baker, Bollinger, Cole | NOOP(4) Armstrong, Cox, Foat, Wall  Bollinger> This is indeed a separate issue from CVE-2000-1123. Add AIX | 5.1 APAR IY29677 to the References for this candidate.  View
5133  CVE-2002-0743  Candidate  mail and mailx in AIX 4.3.3 core dump when called with a very long argument, an indication of a buffer overflow.  Proposed (20020726)  ACCEPT(3) Baker, Bollinger, Cole | NOOP(4) Armstrong, Cox, Foat, Wall  Bollinger> IY29516 is the AIX 4.3 APAR for a variety of buffer | overflows in mail and mailx found during internal testing. (AIX 5.1 | APAR IY28170 needs to be added to the References.) I don"t know if | this is similar to CVE-2002-0041 or not due to the vague description | in the associated advisory. One of the overflows fixed is similar to | CVE-2001-0565, but CVE-2000-0545 does not apply here.  View
5134  CVE-2002-0744  Candidate  namerslv in AIX 4.3.3 core dumps when called with a very long argument, possibly as a result of a buffer overflow.  Proposed (20020726)  ACCEPT(3) Baker, Bollinger, Cole | NOOP(4) Armstrong, Cox, Foat, Wall    View
5135  CVE-2002-0745  Candidate  Buffer overflow in uucp in AIX 4.3.3.  Proposed (20020726)  ACCEPT(3) Baker, Bollinger, Cole | NOOP(4) Armstrong, Cox, Foat, Wall  Bollinger> IY29518 is the AIX 4.3 APAR. AIX 5.1 APAR IY28158 needs to | be added to the References. This candidate only addressed long | arguments to uucp and uux but not the other commands listed in | CVE-2001-1164.  View

Page 20021 of 20943, showing 5 records out of 104715 total, starting on record 100101, ending on 100105

Actions