CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5210 | CVE-2002-0820 | Candidate | FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges. | Proposed (20020830) | ACCEPT(2) Baker, Cole | NOOP(4) Christey, Cox, Foat, Wall | Christey> MISC:http://www.guninski.com/freebsd2.html | Christey> Other OSes besides FreeBSD are affected. | | HP:SSRT0845U | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=104800750626108&w=2 | | CERT-VN:VU#809347 | Need to more closely examine the relationship between | CVE-2002-0820 and CVE-2002-0572, especially with respect to | references. | View |
4187 | CVE-2001-1384 | Candidate | ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp. | Proposed (20020830) | ACCEPT(7) Armstrong, Baker, Cole, Cox, Frech, Green, Wall | NOOP(1) Foat | View | |
5211 | CVE-2002-0821 | Candidate | Buffer overflows in Ethereal 0.9.4 and earlier allow remote attackers to cause a denial of service or execute arbitrary code via (1) the BGP dissector, or (2) the WCP dissector. | Proposed (20020830) | ACCEPT(5) Baker, Cole, Cox, Foat, Green | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:ethereal-bgp-dissector-bo(9497) | XF:ethereal-wcp-dissector-bo(9498) | Christey> REDHAT:RHSA-2002:036 | URL:http://www.redhat.com/support/errata/RHSA-2002-036.html | View |
5469 | CVE-2002-1082 | Candidate | The Image Upload capability for ezContents 1.40 and earlier allows remote attackers to cause ezContents to perform operations on local files as if they were uploaded. | Proposed (20020830) | NOOP(4) Cole, Cox, Foat, Wall | View | |
4190 | CVE-2001-1387 | Candidate | iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak. | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:iptables-iptablessave-information-leak(11116) | XF:iptables-save-files-option(7489) | View |
Page 20878 of 20943, showing 5 records out of 104715 total, starting on record 104386, ending on 104390