CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1001 | CVE-1999-1021 | Entry | NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade. | View | |||
1002 | CVE-1999-1022 | Candidate | serial_ports administrative program in IRIX 4.x and 5.x trusts the user"s PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(2) Christey, Foat | Christey> Note: CVE-1999-1310 is a duplicate of this candidate. | CVE-1999-1310 will be REJECTed; this is the proper CAN to use. | | CIAC:F-01 | URL:http://ciac.llnl.gov/ciac/bulletins/f-01.shtml | SGI:19941001-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/19941001-01-P | MISC:http://www.netsys.com/firewalls/firewalls-9410/0019.html | View |
1003 | CVE-1999-1023 | Candidate | useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired. | Proposed (20010912) | ACCEPT(1) Dik | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Dik> sun bug: 4222400 | Frech> XF:solaris-useradd-expired-accounts(8375) | CONFIRM:(2.6)110883-01, (2.6_x86) 110884-01, (7)110869-01, | (7_x86) 110870-01 | View |
1004 | CVE-1999-1024 | Candidate | ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:tcpdump-ipprint-dos(8373) | View |
1005 | CVE-1999-1025 | Candidate | CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user"s console session when the host is an NIS+ client, which allows others with physical access to login with any string. | Proposed (20010912) | ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | Frech> XF:solaris-cde-nisplus-lock(7473) | Dik> sun bug: 4115685 | View |
Page 201 of 20943, showing 5 records out of 104715 total, starting on record 1001, ending on 1005