CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4963 | CVE-2002-0572 | Candidate | FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files. | Modified (20051217) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Frech> XF:bsd-suid-apps-gain-privileges(8920) | Christey> BSA? Nope. BSD. | Take a closer look at XF:bsd-suid-apps-gain-privileges(8920), | which also references CVE-2002-0820. | Christey> Other OSes besides FreeBSD are affected. | | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2 | Need to more closely examine the relationship between | CVE-2002-0820 and CVE-2002-0572, especially with respect to | references. | Christey> CERT-VN:VU#809347 | URL:http://www.kb.cert.org/vuls/id/809347 | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2 | View |
5576 | CVE-2002-1192 | Candidate | Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file. | Modified (20051218) | ACCEPT(3) Armstrong, Cole, Green | NOOP(1) Cox | View | |
617 | CVE-1999-0635 | Candidate | The echo service is running. | Modified (20060122) | ACCEPT(3) Baker, Northcutt, Wall | REVIEWING(1) Christey | Northcutt> The method to my madness is echo is the common denom in the dos attack | Christey> How much of this is an overlap with the echo/chargen flood | problem (CVE-1999-0103)? If this is only an exposure because | of CVE-1999-0103, then maybe this should be REJECTed. | View |
1381 | CVE-1999-1401 | Candidate | Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook). | Modified (20060309) | ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | Frech> XF:irix-searchbook-permissions(7575) | View |
2755 | CVE-2000-1188 | Candidate | Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter. | Modified (20060413) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Armstrong, Cole, Wall | Frech> XF:quikstore-cgi-read-files(5561) | Armstrong> in Description: change rmeote to remote. | View |
Page 20453 of 20943, showing 5 records out of 104715 total, starting on record 102261, ending on 102265