CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4963  CVE-2002-0572  Candidate  FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.  Modified (20051217)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Frech> XF:bsd-suid-apps-gain-privileges(8920) | Christey> BSA? Nope. BSD. | Take a closer look at XF:bsd-suid-apps-gain-privileges(8920), | which also references CVE-2002-0820. | Christey> Other OSes besides FreeBSD are affected. | | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2 | Need to more closely examine the relationship between | CVE-2002-0820 and CVE-2002-0572, especially with respect to | references. | Christey> CERT-VN:VU#809347 | URL:http://www.kb.cert.org/vuls/id/809347 | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2  View
5576  CVE-2002-1192  Candidate  Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.  Modified (20051218)  ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox    View
617  CVE-1999-0635  Candidate  The echo service is running.  Modified (20060122)  ACCEPT(3) Baker, Northcutt, Wall | REVIEWING(1) Christey  Northcutt> The method to my madness is echo is the common denom in the dos attack | Christey> How much of this is an overlap with the echo/chargen flood | problem (CVE-1999-0103)? If this is only an exposure because | of CVE-1999-0103, then maybe this should be REJECTed.  View
1381  CVE-1999-1401  Candidate  Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).  Modified (20060309)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech  Frech> XF:irix-searchbook-permissions(7575)  View
2755  CVE-2000-1188  Candidate  Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.  Modified (20060413)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall  Frech> XF:quikstore-cgi-read-files(5561) | Armstrong> in Description: change rmeote to remote.  View

Page 20453 of 20943, showing 5 records out of 104715 total, starting on record 102261, ending on 102265

Actions