CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3364 | CVE-2001-0551 | Candidate | Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window. | Modified (20090302) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(2) Christey, Green | Christey> There is some overlap between CVE-2001-0551 and CVE-2001-0772. | CVE-2001-0551 describes a specific vulnerability in | dtprintinfo. HP acknowledges CVE-2001-0551 by stating | that the problem is fixed in HP:HPSBUX0105-151, which | is CVE-2001-0772. But CVE-2001-0772 is a vague advisory | that identifies other vulnerabilities (and vulnerability | types) besides CVE-2001-0551. Perhaps CVE-2001-0772 should | be RECAST to "remove" the reference to dtprintinfo and | leave the other vague descriptions. CVE-2001-0772 and | CVE-2001-0551 are very good examples of the problems that | CVE faces in being consistent with respect to the level of | abstraction, as documented in the CD:SF-CODEBASE, CD:SF-LOC, | and CD:VAGUE content decisions. | Baker> We should rewrite the candidate entry CVE-2001-0772 to address the other issues, and point the dtprintinfo issue to this entry. | Frech> XF:cde-dtprintinfo-bo(8034) | Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2406 - CDE dtprintinfo Help sea rch buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0036.html | BID:4630 | URL:http://www.securityfocus.com/bid/4630 | Christey> CALDERA:CSSA-2002-SCO.30 | Christey> COMPAQ:SSRT2405 | URL:http://www.securityfocus.com/advisories/5997 | BID:8888 | URL:http://www.securityfocus.com/bid/8888 | View |
1583 | CVE-2000-0005 | Candidate | HP-UX aserver program allows local users to gain privileges via a symlink attack. | Modified (20090302) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | RECAST(1) Christey | REVIEWING(1) Levy | Christey> BUGTRAQ:20000102 "HPUX Aserver revisited." indicates that two | different versions of aserver have symlink problems, but with | different files. So CD:SF-LOC says we should split this. | Frech> XF:hp-aserver | Christey> BID:1928 and BID:1930? Which one is being described in | this candidate? | Christey> BID:1930 | View |
4671 | CVE-2002-0279 | Candidate | The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges. | Modified (20090302) | ACCEPT(2) Armstrong, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:hp-setrlimit-kernel-panic(8195) | View |
5188 | CVE-2002-0798 | Candidate | Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service. | Modified (20090302) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Cox, Foat, Wall | View | |
3928 | CVE-2001-1124 | Candidate | rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow. | Modified (20090302) | ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(3) Armstrong, Foat, Wall | RECAST(2) Baker, Christey | Christey> typo: "a malformed RPC portmap requests" | CHANGE> [Christey changed vote from NOOP to RECAST] | Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Baker> MERGE with CVE-2002-0039 | View |
Page 20504 of 20943, showing 5 records out of 104715 total, starting on record 102516, ending on 102520