CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
852 | CVE-1999-0872 | Candidate | Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. | Proposed (19991214) | MODIFY(2) Cole, Frech | NOOP(1) Baker | REJECT(3) Blake, Christey, Stracener | Cole> 611 is the mail to listed above but 759 is for the mail from and | should be listed as a separate vulenrability. | Blake> This does not appear materially different from CVE-1999-0768 | Christey> This is an apparent duplicate of CVE-1999-0768. | REDHAT:RHSA-1999:030-02 describes two issues, one of which is | CVE-1999-0768, and the other is CVE-1999-0769. | Stracener> This is a duplicate of candidate CVE-1999-0768. | Frech> XF:cron-sendmail-bo-root | Christey> BID:759 is improperly assigned to this candidate and doesn"t | even describe it. It may have been inadvertently copied | from CVE-1999-0873. | View |
862 | CVE-1999-0882 | Candidate | Falcon web server allows remote attackers to determine the absolute path of the web root via long file names. | Proposed (19991214) | ACCEPT(3) Baker, Blake, Stracener | MODIFY(1) Frech | NOOP(2) Armstrong, Cole | Frech> XF:falcon-server-long-filename | View |
893 | CVE-1999-0913 | Candidate | dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters. | Proposed (19991214) | ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(4) Armstrong, Baker, Cole, LeBlanc | REVIEWING(1) Christey | Christey> Some voters should use ABSTAIN. | Frech> XF:dragon-fire-ids-metachar(3834) | CHANGE> [Armstrong changed vote from REVIEWING to NOOP] | View |
665 | CVE-1999-0684 | Candidate | Denial of service in Sendmail 8.8.6 in HPUX. | Proposed (19991214) | ACCEPT(2) Blake, Cole | MODIFY(3) Frech, Prosser, Stracener | NOOP(1) Baker | REJECT(1) Christey | Stracener> Add Ref: CIAC: J-040 | Prosser> Might change description to indicate DoS caused by multiple connections | Christey> Andre"s right. This is a duplicate of CVE-1999-0684. | Frech> Without further information and/or references, this issue looks like an | ambiguous version of CVE-1999-0478: Denial of service in HP-UX sendmail | 8.8.6 related to accepting connections. | | (was REJECT) | XF:hp-sendmail-connect-dos | View |
692 | CVE-1999-0712 | Candidate | A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable. | Proposed (19991214) | ACCEPT(4) Baker, Cole, Frech, Stracener | MODIFY(1) Blake | NOOP(1) Armstrong | REVIEWING(1) Christey | Blake> This obscurely-written advisory seems to state that COAS will make the | file world-readable, not that it allows the user to make it so. I hardly | think that allowing the user to turn off security is a vulnerability. | Christey> It"s difficult to write the description based on what"s in | the advisory. If COAS inadvertently changes permissions | without user confirmation, then it should be ACCEPTed with | appropriate modification to the description. | Christey> ADDREF BID:137 | CHANGE> [Armstrong changed vote from REVIEWING to NOOP] | View |
Page 20554 of 20943, showing 5 records out of 104715 total, starting on record 102766, ending on 102770