CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1326 | CVE-1999-1346 | Candidate | PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:pam-rlogin-bypass(8315) | View |
1071 | CVE-1999-1091 | Candidate | UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(2) Cole, Foat | View | |
1327 | CVE-1999-1347 | Candidate | Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:xsession-bypass(8316) | View |
1072 | CVE-1999-1092 | Candidate | tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:tin-insecure-permissions(7796) | Confirmed in changelog for 1.4.1 | http://ftp.kreonet.re.kr/pub/tools/news/tin/v1.4/CHANGES | View |
1328 | CVE-1999-1348 | Candidate | Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service. | Proposed (20010912) | ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:linuxconf-pam-shutdown-dos(8437) | View |
Page 20684 of 20943, showing 5 records out of 104715 total, starting on record 103416, ending on 103420