CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2265 | CVE-2000-0689 | Candidate | Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter. | Modified (20061027) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:account-manager-overwrite-password | In description, you probably want to indicate both Account Manager LITE and PRO. | Because CONFIRM redirects, you may want to verify and normalize to http://www.cgiscriptcenter.com/acctman/index2.html. | Christey> XF:account-manager-overwrite-password | http://xforce.iss.net/static/5125.php | Frech> XF:account-manager-overwrite-password(5125) | View |
2298 | CVE-2000-0722 | Candidate | Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:linux-update-race-condition | Frech> XF:gnome-installer-overwrite-configuration(5129) | View |
2299 | CVE-2000-0723 | Candidate | Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:gnome-installer-overwrite-configuration(5129) | Frech> XF:gnome-installer-overwrite-configuration(5129) | View |
2300 | CVE-2000-0724 | Candidate | The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files. | Proposed (20000921) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall | Christey> XF:go-gnome-preinstaller-symlink(5161) | Frech> XF:go-gnome-preinstaller-symlink(5161) | View |
2268 | CVE-2000-0692 | Candidate | ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set. | Modified (20001010-1) | ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> XF:realsecure-rskill-dos | Christey> CHANGEREF XF:realsecure-rskill-dos to XF:realsecure-frag-syn-dos? | http://xforce.iss.net/static/5133.php | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> In an email to issforum@iss.net on September 7, 2000, ISS says | that Network Sensor 3.2.2 is affected by SYN flooding, but | RealSecure 5.0 is not affected by Syn flooding. In addition, | they could not find conclusive evidence that RS 3.2.2 or 5.0 | was affected by IP fragmentation. This seems to indicate | that there are 2 *possible* problems: syn flooding (acknowledged | by ISS) and fragmentation (unconfirmed). Perhaps this | candidate needs to be split, or its description should be | rewritten to separate the 2 reported problems. | Frech> XF:realsecure-rskill-dos(5133) | View |
Page 20101 of 20943, showing 5 records out of 104715 total, starting on record 100501, ending on 100505