CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1279  CVE-1999-1299  Candidate  rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.  Proposed (20010912)  MODIFY(1) Frech | NOOP(2) Cole, Foat  Frech> XF:rcp-nobody-file-overwrite(7187)  View
2670  CVE-2000-1103  Candidate  rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.  Proposed (20001219)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Wall  Frech> XF:rcvtty-elevate-privileges(5587)  View
2268  CVE-2000-0692  Candidate  ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.  Modified (20001010-1)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> XF:realsecure-rskill-dos | Christey> CHANGEREF XF:realsecure-rskill-dos to XF:realsecure-frag-syn-dos? | http://xforce.iss.net/static/5133.php | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> In an email to issforum@iss.net on September 7, 2000, ISS says | that Network Sensor 3.2.2 is affected by SYN flooding, but | RealSecure 5.0 is not affected by Syn flooding. In addition, | they could not find conclusive evidence that RS 3.2.2 or 5.0 | was affected by IP fragmentation. This seems to indicate | that there are 2 *possible* problems: syn flooding (acknowledged | by ISS) and fragmentation (unconfirmed). Perhaps this | candidate needs to be split, or its description should be | rewritten to separate the 2 reported problems. | Frech> XF:realsecure-rskill-dos(5133)  View
1349  CVE-1999-1369  Candidate  Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> XF:realserver-insecure-password(7544)  View
1858  CVE-2000-0280  Candidate  Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.  Proposed (20000426)  ACCEPT(3) Cole, Levy, Wall | MODIFY(1) Frech | NOOP(1) Baker  Frech> XF:realserver-ramgen-dos  View

Page 20846 of 20943, showing 5 records out of 104715 total, starting on record 104226, ending on 104230

Actions