CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3301  CVE-2001-0484  Candidate  Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.  Modified (20020223-01)  ACCEPT(1) Renaud | MODIFY(2) Baker, Frech | NOOP(6) Balinsky, Cole, Oliver, Wall, Williams, Ziese | REVIEWING(1) Christey  Williams> there was an issue with admin passwd storage for Tektronix Phaser 360, 740, 780, 840 | Frech> XF:tektronix-phaserlink-webserver-backdoor(6482) | Baker> 750DP and 930 printers should be added | http://www.securityfocus.com/archive/1/181007 | CHANGE> [Williams changed vote from REVIEWING to NOOP] | Christey> CVE-1999-1508 covered the older versions discussed | by Ken Williams. These may be duplicates. | This one is BID:2659 | http://www.securityfocus.com/bid/2659  View
3585  CVE-2001-0778  Candidate  OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).  Modified (20020225-01)  ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall    View
3388  CVE-2001-0575  Candidate  Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut.  Modified (20020225-01)  ACCEPT(3) Baker, Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese  Bishop> recommend combining as stated in analysis | Baker> http://support.caldera.com/caldera/solution?11=113723&130=0988647911&14=&2715=&15=&2716=&57=search&58=&2900=dckSSu3pru&25=6&3=SSE072B | "What is SSE072B, the buffer overflow security patch for Openserver 5? (Ref. #113723)" | Buffer overflows have been found in the following 19 | SCO OpenServer 5 utilities: | | /usr/bin/accept | /usr/bin/cancel | /usr/mmdf/bin/deliver | /usr/bin/disable | /usr/bin/enable | /usr/lib/libcurses.a | /usr/bin/lp | /usr/lib/lpadmin | /usr/lib/lpfilter | /usr/lib/lpforms | /usr/lib/lpmove | /usr/lib/lpshut | /usr/bin/lpstat | /usr/lib/lpusers | /usr/bin/recon | /usr/bin/reject | /usr/bin/rmail | /usr/lib/sendmail | /usr/bin/tput | | NOTE: the accept, reject, enable, and disable commands are | symbolically linked to the same binary. | | Running any of the above utilities with a very large argument | can result in a core dump.  View
3389  CVE-2001-0576  Candidate  lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the "-u" command line parameter.  Modified (20020225-01)  ACCEPT(2) Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker  Bishop> recommend combining as stated in analysis | Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem. | Williams> re: Baker recast - why merge 19 separate vuln issues into one CAN?  View
3390  CVE-2001-0577  Candidate  recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.  Modified (20020225-01)  ACCEPT(2) Frech, Williams | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker | REVIEWING(1) Bishop  Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem.  View

Page 20391 of 20943, showing 5 records out of 104715 total, starting on record 101951, ending on 101955

Actions