CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2190  CVE-2000-0614  Candidate  Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.  Proposed (20000719)  ACCEPT(1) Levy | MODIFY(1) Frech | NOOP(4) Cole, LeBlanc, Magdych, Wall | REVIEWING(1) Christey  Christey> This problem appears in AMaViS as well, so they may be the | same codebase. If so, then CD:SF-CODEBASE says to merge the | two (thus ADDREF BID:1461). If they are not the same | codebase, then create a separate candidate for BID:1461. | Frech> XF:linux-tnef-email-overwrite(4915) | CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
2193  CVE-2000-0617  Candidate  Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.  Proposed (20000719)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Magdych, Wall  Frech> XF:xconq-elevate-privileges(4995) | Christey> ADDREF BID:1495 | ADDREF URL:http://www.securityfocus.com/bid/1495 | CHANGE> [Levy changed vote from REVIEWING to ACCEPT] | CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
2194  CVE-2000-0618  Candidate  Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.  Proposed (20000719)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Magdych, Wall  Frech> XF:xconq-elevate-privileges(4995) | Christey> ADDREF BID:1495 | ADDREF URL:http://www.securityfocus.com/bid/1495 | CHANGE> [Levy changed vote from REVIEWING to ACCEPT] | CHANGE> [Magdych changed vote from REVIEWING to NOOP]  View
2199  CVE-2000-0623  Candidate  Buffer overflow in O"Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.  Proposed (20000803)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) LeBlanc | REVIEWING(1) Wall  Frech> XF:website-httpd32-bo(4970) | In the description, I think it"s spelled "referer"  View
2201  CVE-2000-0625  Candidate  NetZero 3.0 and earlier uses weak encryption for storing a user"s login information, which allows a local user to decrypt the password.  Proposed (20000803)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall  Frech> XF:zeroport-weak-encryption(4963)  View

Page 20590 of 20943, showing 5 records out of 104715 total, starting on record 102946, ending on 102950

Actions