CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3420  CVE-2001-0607  Candidate  asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.  Modified (20090302)  ACCEPT(5) Baker, Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey  Frech> XF:hp-asecure-dos(6212) | Possible duplicate of CVE-2000-0083: HP asecure creates the | Audio Security File audio.sec with insecure permissions, which allows | local users to cause a denial of service or gain additional | privileges. | Williams> Frech - this is not a dupe of CVE-2000-0083. | Christey> While this advisory is vaguely worded, the fact that HP did an | advisory for the other asecure problem (now CVE-2000-0083) | indicates at the very least that this problem occurs in | a different version than CVE-2000-0083, so CD:SF-LOC | suggests a SPLIT. However, the HP advisory says "10.X" | and "11.X" are affected, so who knows what versions they | *really* mean? | CHANGE> [Christey changed vote from NOOP to REVIEWING]  View
104  CVE-1999-0104  Candidate  A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.  Modified (20090302)  ACCEPT(2) Frech, Wall | REVIEWING(1) Christey  Wall> Another reference is Microsoft Knowledge Base Q179129. | Christey> Not sure how many separate "instances" of Teardrop there are. | See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258 | Christey> See the SCO advisory at: | http://www.securityfocus.com/templates/advisory.html?id=1411 | which may further clarify the issue. | Christey> MSKB:Q179129 | http://support.microsoft.com/support/kb/articles/q179/1/29.asp | Christey> MSKB:Q179129 | http://support.microsoft.com/support/kb/articles/q179/1/29.asp | Note that the hotfix name is teardrop2, but the keywords | included in the KB article specifically name bonk | (CVE-1999-0258) and boink. | Since teardrop2 was fixed in a slightly different version | (at least in a separate patch) than Teardrop, CD:SF-LOC | suggests keeping them separate. | Christey> Add period to the end of the description.  View
4968  CVE-2002-0577  Candidate  Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.  Modified (20090302)  ACCEPT(3) Baker, Cole, Frech | NOOP(3) Cox, Foat, Wall    View
5741  CVE-2002-1357  Candidate  Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.  Modified (20090302)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(1) Cox | REVIEWING(1) Wall  Frech> XF:ssh-transport-length-bo(10868)  View
5742  CVE-2002-1358  Candidate  Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.  Modified (20090302)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Cox | REVIEWING(1) Wall  Frech> XF:ssh-transport-empty-lists-bo(10869)  View

Page 20505 of 20943, showing 5 records out of 104715 total, starting on record 102521, ending on 102525

Actions