CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2582  CVE-2000-1013  Candidate  The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.  Proposed (20001129)  ACCEPT(2) Cole, Mell | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:freebsd-display-read-files(5645)  View
2635  CVE-2000-1066  Candidate  The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.  Modified (20010119-01)  ACCEPT(2) Cole, Mell | MODIFY(1) Frech | NOOP(1) Renaud  Frech> XF:getnameinfo-dos(5454)  View
2331  CVE-2000-0755  Candidate  Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.  Proposed (20000921)  ACCEPT(2) Cole, Levy | NOOP(2) Baker, Wall | REJECT(2) Christey, Frech  Christey> DUPE CVE-2000-0730 | Also, the BID is wrong. | Frech> DUPE OF CVE-2000-0730 | Also, the BID is wrong.  View
1820  CVE-2000-0242  Candidate  WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.  Proposed (20000412)  ACCEPT(2) Cole, Levy | NOOP(1) Baker | RECAST(1) Frech | REJECT(2) Christey, Magdych  Frech> Violation of fundamentum divisionis (that is, it"s more than one issue) and | a potential nitpick: | - windmail-fileread: allows remote attackers to read arbitrary files | - windmail-pipe-command: execute commands via shell metacharacters | - The conjunction "or" should be "and", if you decide to stick with one CAN. | Christey> As Andre basically said without naming content decisions, | CD:SF-LOC says this should be split. | | HOWEVER - the author of the product says that WindMail isn"t | supposed to be a CGI script, and says that the pipe | character problem is not related to Geocel. So should CVE | record when someone runs a program that wasn"t intended to | be a CGI? There may be a level of abstraction issue here. | Note that Perl and shell interpreters in CGI-BIN are | already mentioned in CVE-1999-0509. If we want to include | "using a program that wasn"t designed to be a CGI" as a | problem, we should have a separate candidate. | | See the author"s comments at: | http://www.securityfocus.com/templates/archive.pike?list=1&msg=3.0.5.32.20000331114325.013af680@mailhost.geocel.com | | which also claims that the original announcer hasn"t provided | any more details after the author was unable to reproduce the | problem. | CHANGE> [Magdych changed vote from REVIEWING to REJECT] | Magdych> After reviewing the author"s comments, I"m inclined to think that this is more of a misconfiguration than a vulnerability.  View
2332  CVE-2000-0756  Candidate  Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(2) Frech, LeBlanc | REVIEWING(2) Christey, Wall  LeBlanc> - if a KB article, bulletin, or patch can be found, then | I"ll ACCEPT | Christey> This is the same as MS:MS01-012 (CVE-2001-0145) | See the Bugtraq post by Joel Moses: | http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2 | | As of this writing, it is not certain which candidate | should be preferred: the candidate that has been publicly | known longer (i.e. CVE-2000-0756), or the more "official" | candidate, which has probably been publicized more (i.e. | CVE-2001-0145). | Frech> XF:outlook-vcard-dos(5175) | XF:outlook-vcard-bo(6145) | Because there"s another more recent CAN linked to @stake and | Microsoft"s advisories, we"ll link both of our records to both | candiates until a final decision occurs. If a decision has been made | to promote the CVE-2001 entry, then enter my vote as a REJECT for | CVE-2000-0756. | Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175)  View

Page 20098 of 20943, showing 5 records out of 104715 total, starting on record 100486, ending on 100490

Actions