CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
170 | CVE-1999-0170 | Entry | Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. | View | |||
169 | CVE-1999-0169 | Candidate | NFS allows attackers to read and write any file on the system by specifying a false UID. | Proposed (19990714) | ACCEPT(2) Frech, Northcutt | MODIFY(1) Baker | REJECT(1) Shostack | Shostack> this is not a vulnerability but a design feature. | Baker> Maybe we should reword it so that it is clear that this was a problem to something like: | | "A remote attacker could read/write files to the system with root-level permissions on NFS servers that fail to properly check the UID." | View |
168 | CVE-1999-0168 | Entry | The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions. | View | |||
167 | CVE-1999-0167 | Entry | In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system. | View | |||
166 | CVE-1999-0166 | Entry | NFS allows users to use a "cd .." command to access other directories besides the exported file system. | View |
Page 20910 of 20943, showing 5 records out of 104715 total, starting on record 104546, ending on 104550