CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1379  CVE-1999-1399  Candidate  spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.  Proposed (20010912)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:spaceware-hostname-command-execution(7194)  View
1006  CVE-1999-1026  Candidate  aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.  Proposed (20010912)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Foat  Frech> XF:sun-aspppd-tmp-symlink(7173)  View
1745  CVE-2000-0167  Candidate  IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.  Proposed (20000223)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(4) Christey, LeBlanc, Levy, Wall  Frech> XF:iis-pickup-directory-dos | Christey> BID:1819 | URL:http://www.securityfocus.com/bid/1819 | LeBlanc> Trying to get more info  View
5794  CVE-2002-1410  Candidate  Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> ADD: http://bosen.net/advisories/aresu-adv.002.txt  View
5795  CVE-2002-1411  Candidate  Directory traversal vulnerability in update.dpgs in Duma Photo Gallery System (DPGS) 0.99.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the id parameter.  Proposed (20030317)  ACCEPT(1) Cole | MODIFY(1) Baker | NOOP(2) Cox, Wall  Baker> Since the vendor no longer maintains the code, no fix appears available. | The dpgs.pll file has insufficient filtering to preclude this, so a fix | should not be too difficult to make and should be straightforward. | The description should probably reflect that the lax filtering in | the dpgs.pll file allows form to be posted with the directory traversal | and null byte data.  View

Page 20299 of 20943, showing 5 records out of 104715 total, starting on record 101491, ending on 101495

Actions