CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2900  CVE-2001-0079  Candidate  Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.  Proposed (20010202)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:stm-log-files-symlink(6126) | BID-2158  View
2903  CVE-2001-0082  Candidate  Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.  Proposed (20010202)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese  Frech> XF:fw1-bypass-rules(6000) | BID-2143  View
2905  CVE-2001-0084  Candidate  GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.  Proposed (20010202)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(5) Christey, Cole, Prosser, Wall, Ziese  Frech> XF:gtk-module-execute-code(5832) | Christey> XF:gtk-module-execute-code | URL:http://xforce.iss.net/static/5832.php | Christey> TURBO:TLSA2001026 | URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000440.html  View
2907  CVE-2001-0086  Candidate  CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View
2908  CVE-2001-0087  Candidate  itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.  Proposed (20010202)  ACCEPT(1) Frech | NOOP(3) Cole, Wall, Ziese    View

Page 20627 of 20943, showing 5 records out of 104715 total, starting on record 103131, ending on 103135

Actions