CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
30 | CVE-1999-0030 | Candidate | root privileges via buffer overflow in xlock command on SGI IRIX systems. | Proposed (19990623) | ACCEPT(3) Levy, Ozancin, Prosser | NOOP(1) Baker | RECAST(1) Frech | REJECT(1) Christey | Frech> XF:xlock-bo (also add) | As per xlock-bo, also appears on AIX, BSDI, DG/UX, FreeBSD, Solaris, and | several Linii. | Also, don"t you mean to cite SGI:19970502-02-PX? The one you list is | login/scheme. | Levy> Notice that this xlock overflow is the same as in | CA-97.13. CA-97.21 simply is a reminder. | Christey> As pointed out by Elias, CA-97.21 states: "For more | information about vulnerabilities in xlock... see CA-97.13" | CA-97.13 = CVE-1999-0038. | This may also be a duplicate with CVE-1999-0306. | | See exploits at: | | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418394&w=2 | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418404&w=2 | | Sun also has this problem, at | http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/150&type=0&nav=sec.sba | View |
4878 | CVE-2002-0486 | Candidate | Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges. | Proposed (20020611) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:xpede-password-weak-encryption(8614) | View |
1327 | CVE-1999-1347 | Candidate | Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm. | Proposed (20010912) | MODIFY(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> XF:xsession-bypass(8316) | View |
2054 | CVE-2000-0476 | Candidate | xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized. | Proposed (20000712) | ACCEPT(2) Levy, Ozancin | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall | Frech> XF:xterm-control-characters-dos(4987) | View |
2743 | CVE-2000-1176 | Candidate | Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field. | Proposed (20001219) | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:yabb-search-format-string(5501) | View |
Page 20893 of 20943, showing 5 records out of 104715 total, starting on record 104461, ending on 104465