CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1890 | CVE-2000-0312 | Candidate | cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron"s fake popen function. | Proposed (20010214) | ACCEPT(3) Baker, Cole, Collins | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:cron-sendmail-root(3335) | Seems like this issue is not just OpenBSD, and is described | differently by other vendors: | SuSE Security Announcement #15 Security hole in cron | http://www.suse.de/de/support/security/suse_security_announce_15.txt | Red Hat, Inc. Security Advisory RHSA-1999:030-02 Buffer overflow in | cron daemon | http://www.redhat.com/support/errata/rh52-errata-general.html#vixie-cron | Caldera Systems, Inc. Security Advisory CSSA-1999-023.0 serious security | problem in cron | http://www.calderasystems.com/support/security/advisories/CSSA-1999-023.0.tx | t | All are dated on or around 1999-08-27 to 1999-08-30. | Also, may overlap with CVE-1999-0769: Vixie Cron on Linux systems allows | local users to set parameters of sendmail commands via the MAILTO | environmental variable. | Christey> See Andre"s comments, but I believe this is different than | CVE-1999-0769. Also consider CVE-1999-0768 and CVE-1999-0872 | (Vixie Cron buffer overflow via MAILTO), | View |
358 | CVE-1999-0359 | Candidate | ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords. | Proposed (20010214) | ACCEPT(2) Cole, Frech | MODIFY(1) Baker | Frech> XF:ptylogin-dos | Baker> Should say "... lock out a modem, ..." rather than "... locking out modems..." | View |
2928 | CVE-2001-0107 | Candidate | Veritas Backup agent on Linux allows remote attackers to cause a denial of service by establishing a connection without sending any data, which causes the process to hang. | Proposed (20010214) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:veritas-backupexec-dos | URL:http://xforce.iss.net/static/5941.php | Frech> XF:veritas-backupexec-dos(5941) | Christey> BUGTRAQ:19990903 DOS in Backup Exec Agent | http://marc.theaimsgroup.com/?l=bugtraq&m=93685651407299&w=2 | View |
2934 | CVE-2001-0113 | Candidate | statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script. | Proposed (20010214) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:omnihttpd-statsconfig-execute-code | URL:http://xforce.iss.net/static/5956.php | Frech> XF:omnihttpd-statsconfig-execute-code(5956) | View |
2935 | CVE-2001-0114 | Candidate | statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter. | Proposed (20010214) | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall | Christey> XF:omnihttpd-statsconfig-corrupt-files | URL:http://xforce.iss.net/static/5955.php | Frech> XF:omnihttpd-statsconfig-corrupt-files(5955) | Christey> MISC:http://www.omnicron.ca/httpd/docs/release.html | May be vague acknowledgement; need to ask | mailto:support@omnicron.ca?subject=OmniHTTPd Technical Support | (and ask them about the other OmniHTTP issues as well) | View |
Page 20630 of 20943, showing 5 records out of 104715 total, starting on record 103146, ending on 103150