CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3240  CVE-2001-0422  Entry  Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.        View
3239  CVE-2001-0421  Candidate  FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.  Proposed (20010524)  ACCEPT(1) Cole | MODIFY(2) Dik, Frech | NOOP(1) Wall | REVIEWING(2) Williams, Ziese  Frech> XF:solaris-ftp-shadow-recovery(6422) | Dik> sun bug ids: 4436988 | | The "world-readable" core dump problem does not exist in | Solaris 8 and other Solaris releases which have been patched | to include the "coreadm" command and possibly earlier (many release | have been patched to avoid core dumps in more situations and | always make them mode 0600) | | Solaris 8 was the first release to contain coreadm initially | (backported and include in 2.6 & 7) | Solaris 7 was the first release to make core dumps mode 0600. | (fix backported to 2.6 and earlier)  View
3238  CVE-2001-0420  Candidate  Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:talkback-cgi-read-files(6340) | Christey> BID:2547 | URL:http://www.securityfocus.com/bid/2547  View
3237  CVE-2001-0419  Candidate  Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:oracle-appserver-ndwfn4-bo(6334) | Christey> At http://otn.oracle.com/deploy/security/alerts.htm, | in an item titled "Oracle Application Server Buffer Overflow," | Oracle says that it was "Unable to reproduce vulnerability"  View
3236  CVE-2001-0418  Candidate  content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.  Proposed (20010524)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:ncm-content-database-access(6386)  View

Page 20296 of 20943, showing 5 records out of 104715 total, starting on record 101476, ending on 101480

Actions