CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3240 | CVE-2001-0422 | Entry | Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable. | View | |||
3239 | CVE-2001-0421 | Candidate | FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition. | Proposed (20010524) | ACCEPT(1) Cole | MODIFY(2) Dik, Frech | NOOP(1) Wall | REVIEWING(2) Williams, Ziese | Frech> XF:solaris-ftp-shadow-recovery(6422) | Dik> sun bug ids: 4436988 | | The "world-readable" core dump problem does not exist in | Solaris 8 and other Solaris releases which have been patched | to include the "coreadm" command and possibly earlier (many release | have been patched to avoid core dumps in more situations and | always make them mode 0600) | | Solaris 8 was the first release to contain coreadm initially | (backported and include in 2.6 & 7) | Solaris 7 was the first release to make core dumps mode 0600. | (fix backported to 2.6 and earlier) | View |
3238 | CVE-2001-0420 | Candidate | Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | Frech> XF:talkback-cgi-read-files(6340) | Christey> BID:2547 | URL:http://www.securityfocus.com/bid/2547 | View |
3237 | CVE-2001-0419 | Candidate | Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:oracle-appserver-ndwfn4-bo(6334) | Christey> At http://otn.oracle.com/deploy/security/alerts.htm, | in an item titled "Oracle Application Server Buffer Overflow," | Oracle says that it was "Unable to reproduce vulnerability" | View |
3236 | CVE-2001-0418 | Candidate | content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:ncm-content-database-access(6386) | View |
Page 20296 of 20943, showing 5 records out of 104715 total, starting on record 101476, ending on 101480