CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3983  CVE-2001-1179  Candidate  xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.  Proposed (20020315)  MODIFY(1) Frech | NOOP(6) Armstrong, Cole, Foat, Green, Wall, Ziese  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:xfree86-xman-manpath-privileges(8716)  View
4495  CVE-2002-0101  Candidate  Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.  Proposed (20020315)  ACCEPT(4) Foat, Frech, Green, Ziese | NOOP(1) Cole | REVIEWING(1) Wall  Ziese> would seem appropriate as a CVE entry. | CHANGE> [Foat changed vote from NOOP to ACCEPT]  View
4498  CVE-2002-0104  Candidate  AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese    View
4499  CVE-2002-0105  Candidate  CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey  Christey> CALDERA:CSSA-2002-SCO.18 | XF:cde-dt-world-writable(9045) | URL:http://www.iss.net/security_center/static/9045.php | Note: the advisory sort-of implies that world-write | permissions were the key problem, so the fact that a symlink | attack could take place did not necessarily mean that a | symlink following vulnerability really existed, in the sense | that symlink attacks don"t exist in directories that are | not writable by other users (well, without those users | exploiting some *other* vulnerability to allow them to create | the symlink!) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Hmmm... should XF:cde-dt-world-writable(9045) really be added | here? ISS may have "split" between the permissions issue | and the symlink problem.  View
3988  CVE-2001-1184  Candidate  wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024.  Proposed (20020315)  ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall    View

Page 20780 of 20943, showing 5 records out of 104715 total, starting on record 103896, ending on 103900

Actions