CVE List

Id CVE No. Status Description Phase Votes Comments Actions
852  CVE-1999-0872  Candidate  Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.  Proposed (19991214)  MODIFY(2) Cole, Frech | NOOP(1) Baker | REJECT(3) Blake, Christey, Stracener  Cole> 611 is the mail to listed above but 759 is for the mail from and | should be listed as a separate vulenrability. | Blake> This does not appear materially different from CVE-1999-0768 | Christey> This is an apparent duplicate of CVE-1999-0768. | REDHAT:RHSA-1999:030-02 describes two issues, one of which is | CVE-1999-0768, and the other is CVE-1999-0769. | Stracener> This is a duplicate of candidate CVE-1999-0768. | Frech> XF:cron-sendmail-bo-root | Christey> BID:759 is improperly assigned to this candidate and doesn"t | even describe it. It may have been inadvertently copied | from CVE-1999-0873.  View
862  CVE-1999-0882  Candidate  Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.  Proposed (19991214)  ACCEPT(3) Baker, Blake, Stracener | MODIFY(1) Frech | NOOP(2) Armstrong, Cole  Frech> XF:falcon-server-long-filename  View
893  CVE-1999-0913  Candidate  dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.  Proposed (19991214)  ACCEPT(2) Blake, Stracener | MODIFY(1) Frech | NOOP(4) Armstrong, Baker, Cole, LeBlanc | REVIEWING(1) Christey  Christey> Some voters should use ABSTAIN. | Frech> XF:dragon-fire-ids-metachar(3834) | CHANGE> [Armstrong changed vote from REVIEWING to NOOP]  View
665  CVE-1999-0684  Candidate  Denial of service in Sendmail 8.8.6 in HPUX.  Proposed (19991214)  ACCEPT(2) Blake, Cole | MODIFY(3) Frech, Prosser, Stracener | NOOP(1) Baker | REJECT(1) Christey  Stracener> Add Ref: CIAC: J-040 | Prosser> Might change description to indicate DoS caused by multiple connections | Christey> Andre"s right. This is a duplicate of CVE-1999-0684. | Frech> Without further information and/or references, this issue looks like an | ambiguous version of CVE-1999-0478: Denial of service in HP-UX sendmail | 8.8.6 related to accepting connections. | | (was REJECT) | XF:hp-sendmail-connect-dos  View
692  CVE-1999-0712  Candidate  A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.  Proposed (19991214)  ACCEPT(4) Baker, Cole, Frech, Stracener | MODIFY(1) Blake | NOOP(1) Armstrong | REVIEWING(1) Christey  Blake> This obscurely-written advisory seems to state that COAS will make the | file world-readable, not that it allows the user to make it so. I hardly | think that allowing the user to turn off security is a vulnerability. | Christey> It"s difficult to write the description based on what"s in | the advisory. If COAS inadvertently changes permissions | without user confirmation, then it should be ACCEPTed with | appropriate modification to the description. | Christey> ADDREF BID:137 | CHANGE> [Armstrong changed vote from REVIEWING to NOOP]  View

Page 20554 of 20943, showing 5 records out of 104715 total, starting on record 102766, ending on 102770

Actions