CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1406 | CVE-1999-1426 | Candidate | Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files. | Proposed (20010912) | ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | Frech> XF:solaris-adminsuite-symlink(7469) | Dik> sun bug: 1262888 | View |
1151 | CVE-1999-1171 | Candidate | IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:wsftp-registry(1726) | View |
1407 | CVE-1999-1427 | Candidate | Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges. | Proposed (20010912) | ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | Frech> XF:solaris-adminsuite-lock-file(7470) | Dik> sun bug: 1262888 | View |
1152 | CVE-1999-1172 | Candidate | By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey | Christey> The discloser does not provide enough details to fully | understand what the problem is. This makes it difficult | because if Maximizer has a concept of "users" and it is | designed to allow any user to modify any other user"s data, | then this would not be a vulnerability or exposure, unless | that "cross-user" capability could be used to violate system | integrity, data confidentiality, or the like. There are some | features of Maximizer 6.0 that, if abused, could allow someone | to do some bad things. For example, an attacker could modify | the email addresses for contacts to redirect sales to | locations besides the customer. There"s also a capability of | assigning priorities and alarms, which could be susceptible to | an "inconvenience attack" at the very least, as well as | tie-ins to e-commerce capabilities. | | The critical question becomes: "how is this data shared" in | the first place? If it"s through a network share or other | distribution method besides transferring the complete database | between sites, then this may be accessible to any attacker who | can mimic a Maximizer client (if there is such a thing as a | client), and this could be a vulnerability or exposure | according to the CVE definition. | | However, since the Maximizer functionality is unknown to me | and not readily apparent from product documentation, it"s hard | to know what to do about this one. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:maximizer-enterprise-calendar-modification(7590) | View |
1408 | CVE-1999-1428 | Candidate | Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges. | Proposed (20010912) | ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | Frech> XF:solaris-adminsuite-database-manager(7471) | Dik> sun bug: 4005611 | View |
Page 20701 of 20943, showing 5 records out of 104715 total, starting on record 103501, ending on 103505