CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3499  CVE-2001-0691  Candidate  Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.  Modified (20020817-01)  ACCEPT(6) Armstrong, Baker, Bishop, Cole, Prosser, Ziese | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Prosser> http://www.linux-mandrake.com/en/updates/2001/MDKSA-2001-054.php3?dis=7.1 | Frech> XF:imap-ipop2d-ipop3d-bo(6269) | Christey> ADDREF RHSA-2001:094 (per Mark Cox of Red Hat)  View
4032  CVE-2001-1228  Candidate  Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.  Modified (20020817-01)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(3) Christey, Cox, Foat  Christey> NETBSD:NetBSD-SA2002-002 | URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-002.txt.asc | Frech> XF:gzip-long-filename-bo(7882)  View
4555  CVE-2002-0162  Candidate  LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.  Modified (20020817-01)  ACCEPT(4) Armstrong, Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Christey> Modify the desc: it"s temporary *directory* creation. | | XF:logwatch-tmp-race-condition(8652) | URL:http://www.iss.net/security_center/static/8652.php | BID:4374 | URL:http://online.securityfocus.com/bid/4374 | Frech> XF:logwatch-tmp-race-condition(8652)  View
4558  CVE-2002-0165  Candidate  LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CVE-2002-0162.  Modified (20020817-01)  ACCEPT(4) Armstrong, Cole, Cox, Green | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Christey> XF:logwatch-tmp-race-condition(8652) | URL:http://www.iss.net/security_center/static/8652.php | CONFIRM:http://list.kaybee.org/archives/logwatch-announce/2002-March/000003.html | (notice how this is a different announcement than CVE-2002-0162) | Frech> XF:logwatch-tmp-race-condition(8652)  View
3813  CVE-2001-1009  Candidate  Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.  Modified (20020817-01)  ACCEPT(4) Armstrong, Baker, Cole, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:fetchmail-signed-integer-index(6965)  View

Page 20397 of 20943, showing 5 records out of 104715 total, starting on record 101981, ending on 101985

Actions