CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1379 | CVE-1999-1399 | Candidate | spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:spaceware-hostname-command-execution(7194) | View |
1006 | CVE-1999-1026 | Candidate | aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:sun-aspppd-tmp-symlink(7173) | View |
1745 | CVE-2000-0167 | Candidate | IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory. | Proposed (20000223) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(4) Christey, LeBlanc, Levy, Wall | Frech> XF:iis-pickup-directory-dos | Christey> BID:1819 | URL:http://www.securityfocus.com/bid/1819 | LeBlanc> Trying to get more info | View |
5794 | CVE-2002-1410 | Candidate | Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> ADD: http://bosen.net/advisories/aresu-adv.002.txt | View |
5795 | CVE-2002-1411 | Candidate | Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter. | Proposed (20030317) | ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall | Baker> Since the vendor no longer maintains the code, no fix appears available. | The dpgs.pll file has insufficient filtering to preclude this, so a fix | should not be too difficult to make and should be straightforward. | The description should probably reflect that the lax filtering in | the dpgs.pll file allows form to be posted with the directory traversal | and null byte data. | View |
Page 20299 of 20943, showing 5 records out of 104715 total, starting on record 101491, ending on 101495