CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1406  CVE-1999-1426  Candidate  Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.  Proposed (20010912)  ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech  Frech> XF:solaris-adminsuite-symlink(7469) | Dik> sun bug: 1262888  View
1151  CVE-1999-1171  Candidate  IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:wsftp-registry(1726)  View
1407  CVE-1999-1427  Candidate  Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.  Proposed (20010912)  ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech  Frech> XF:solaris-adminsuite-lock-file(7470) | Dik> sun bug: 1262888  View
1152  CVE-1999-1172  Candidate  By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Christey  Christey> The discloser does not provide enough details to fully | understand what the problem is. This makes it difficult | because if Maximizer has a concept of "users" and it is | designed to allow any user to modify any other user"s data, | then this would not be a vulnerability or exposure, unless | that "cross-user" capability could be used to violate system | integrity, data confidentiality, or the like. There are some | features of Maximizer 6.0 that, if abused, could allow someone | to do some bad things. For example, an attacker could modify | the email addresses for contacts to redirect sales to | locations besides the customer. There"s also a capability of | assigning priorities and alarms, which could be susceptible to | an "inconvenience attack" at the very least, as well as | tie-ins to e-commerce capabilities. | | The critical question becomes: "how is this data shared" in | the first place? If it"s through a network share or other | distribution method besides transferring the complete database | between sites, then this may be accessible to any attacker who | can mimic a Maximizer client (if there is such a thing as a | client), and this could be a vulnerability or exposure | according to the CVE definition. | | However, since the Maximizer functionality is unknown to me | and not readily apparent from product documentation, it"s hard | to know what to do about this one. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:maximizer-enterprise-calendar-modification(7590)  View
1408  CVE-1999-1428  Candidate  Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.  Proposed (20010912)  ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech  Frech> XF:solaris-adminsuite-database-manager(7471) | Dik> sun bug: 4005611  View

Page 20701 of 20943, showing 5 records out of 104715 total, starting on record 103501, ending on 103505

Actions