CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4571  CVE-2002-0178  Entry  uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands.        View
10691  CVE-2004-2265  Candidate  UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact.  Assigned (20050719)  None (candidate not yet proposed)    View
32383  CVE-2008-2266  Candidate  uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.  Assigned (20080516)  None (candidate not yet proposed)    View
3679  CVE-2001-0873  Entry  uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option.        View
7406  CVE-2003-0579  Candidate  uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.  Assigned (20030716)  None (candidate not yet proposed)    View

Page 20367 of 20943, showing 5 records out of 104715 total, starting on record 101831, ending on 101835

Actions