CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1467  CVE-1999-1487  Candidate  Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.  Modified (20020218-01)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech  Frech> XF:aix-digest(7477)  View
1275  CVE-1999-1295  Candidate  Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.  Modified (20020218-01)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:dfs-login-groups(7154)  View
1534  CVE-1999-1554  Candidate  /usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.  Modified (20020218-01)  ACCEPT(2) Cole, Stracener | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:sgi-irix-reset(3164) | CHANGE> [Foat changed vote from ACCEPT to NOOP]  View
2850  CVE-2001-0029  Candidate  Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.  Modified (20020222-01)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(3) Christey, Wall, Ziese  Frech> XF:oops-dns-bo(6122) | Christey> This looks like a different overflow than the one described | in the original post at: | http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html | The vendor does acknowledge *that* problem in the 1.5.0 | comments of | http://zipper.paco.net/~igor/oops/ChangeLog | Christey> Vendor fixed this problem between 1.4.22 and 1.5.5, based | on a source code comparison. | CD:SF-LOC says that bugs of the same type, that appear in | different versions, must be SPLIT. Therefore this should | stay separate from CVE-2001-0028. | | Change MISC to CONFIRM. The comments for version 1.5.4 | say "more sprintf/strncpy fixes" and that"s the type of | changes that were made in lib.c, the code that was listed | in the Bugtraq post for this CAN.  View
2402  CVE-2000-0833  Candidate  Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.  Modified (20020222-01)  ACCEPT(5) Baker, Cole, Collins, Frech, Wall | NOOP(2) Armstrong, Magdych  Cole> HAS-INDEPENDENT-CONFIRMATION | CHANGE> [Wall changed vote from REVIEWING to ACCEPT]  View

Page 20389 of 20943, showing 5 records out of 104715 total, starting on record 101941, ending on 101945

Actions