CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3600  CVE-2001-0794  Candidate  Buffer overflow in A-FTP Anonymous FTP Server allows remote attackers to cause a denial of service via a long USER command.  Proposed (20011012)  MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> XF:softhead-aftp-bo(6729)  View
3264  CVE-2001-0447  Candidate  Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:software602-lan-suite-bo(5583) | Possible duplicate or close similarity with | BID-1979/CVE-2000-1115. | Christey> The BID doesn"t look quite like this; I think it"s for | CVE-2001-0448  View
3265  CVE-2001-0448  Candidate  Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.  Proposed (20010524)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese  Frech> XF:software602-lan-suite-bo(5583) | Christey> This should be BID:2514 (and CVE-2001-0447 should have | BID:2514 removed from its set of references)  View
1633  CVE-2000-0055  Candidate  Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.  Proposed (20000125)  MODIFY(2) Baker, Frech | NOOP(1) Dik  Frech> XF:sol-chkperm-bo(3870) | Dik> chkperm runs set-uid bin, so initially the access granted | will be user bin, not root. (Though bin access can easily be leveraged | to root access, less so in Solaris 8+) | Also, there is reason to believe this bug is not exploitable; the buffer | overflown is declared in the stack in main(); yet, the program never | returns from main() but calls exit instead so any damage to return addresses | is never noticed. | Baker> Maybe the details from Caspar could be included, or modify the description somewhat  View
1408  CVE-1999-1428  Candidate  Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.  Proposed (20010912)  ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech  Frech> XF:solaris-adminsuite-database-manager(7471) | Dik> sun bug: 4005611  View

Page 20861 of 20943, showing 5 records out of 104715 total, starting on record 104301, ending on 104305

Actions