CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3364  CVE-2001-0551  Candidate  Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.  Modified (20090302)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(2) Christey, Green  Christey> There is some overlap between CVE-2001-0551 and CVE-2001-0772. | CVE-2001-0551 describes a specific vulnerability in | dtprintinfo. HP acknowledges CVE-2001-0551 by stating | that the problem is fixed in HP:HPSBUX0105-151, which | is CVE-2001-0772. But CVE-2001-0772 is a vague advisory | that identifies other vulnerabilities (and vulnerability | types) besides CVE-2001-0551. Perhaps CVE-2001-0772 should | be RECAST to "remove" the reference to dtprintinfo and | leave the other vague descriptions. CVE-2001-0772 and | CVE-2001-0551 are very good examples of the problems that | CVE faces in being consistent with respect to the level of | abstraction, as documented in the CD:SF-CODEBASE, CD:SF-LOC, | and CD:VAGUE content decisions. | Baker> We should rewrite the candidate entry CVE-2001-0772 to address the other issues, and point the dtprintinfo issue to this entry. | Frech> XF:cde-dtprintinfo-bo(8034) | Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2406 - CDE dtprintinfo Help sea rch buffer overflow vulnerability | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0036.html | BID:4630 | URL:http://www.securityfocus.com/bid/4630 | Christey> CALDERA:CSSA-2002-SCO.30 | Christey> COMPAQ:SSRT2405 | URL:http://www.securityfocus.com/advisories/5997 | BID:8888 | URL:http://www.securityfocus.com/bid/8888  View
1583  CVE-2000-0005  Candidate  HP-UX aserver program allows local users to gain privileges via a symlink attack.  Modified (20090302)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | RECAST(1) Christey | REVIEWING(1) Levy  Christey> BUGTRAQ:20000102 "HPUX Aserver revisited." indicates that two | different versions of aserver have symlink problems, but with | different files. So CD:SF-LOC says we should split this. | Frech> XF:hp-aserver | Christey> BID:1928 and BID:1930? Which one is being described in | this candidate? | Christey> BID:1930  View
4671  CVE-2002-0279  Candidate  The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges.  Modified (20090302)  ACCEPT(2) Armstrong, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:hp-setrlimit-kernel-panic(8195)  View
5188  CVE-2002-0798  Candidate  Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service.  Modified (20090302)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Cox, Foat, Wall    View
3928  CVE-2001-1124  Candidate  rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow.  Modified (20090302)  ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(3) Armstrong, Foat, Wall | RECAST(2) Baker, Christey  Christey> typo: "a malformed RPC portmap requests" | CHANGE> [Christey changed vote from NOOP to RECAST] | Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Baker> MERGE with CVE-2002-0039  View

Page 20504 of 20943, showing 5 records out of 104715 total, starting on record 102516, ending on 102520

Actions