CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1525  CVE-1999-1545  Candidate  Joe"s Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.  Proposed (20010912)  NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech  Frech> (ACCEPT; Task 2358)  View
3121  CVE-2001-0300  Candidate  oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.  Modified (20050509)  NOOP(3) Cole, Wall, Ziese | REJECT(1) Frech | REVIEWING(1) Bishop  Frech> Validity threshold is not met by the references cited. Would | be willing to reassess and change vote if more information is | forthcoming.  View
1595  CVE-2000-0017  Candidate  Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.  Proposed (20000111)  NOOP(4) Armstrong, Baker, Christey, Stracener | REJECT(2) Frech, Levy  Christey> It"s not certain whether this is exploitable or not. An | expert (the linuxconf author?) wasn"t able to duplicate the | bug - see http://lwn.net/1999/1223/a/linuxconfresponse.html | | The original posting with example exploit was | http://marc.theaimsgroup.com/?l=bugtraq&m=94580196627059&w=2 | | However - GIAC and the Security Focus incidents list have | consistently reported that scans are taking place for | linuxconf, so do the hackers know more than we do? | Frech> Unless vendor or other confirmation occurs, there has been no corroboration | of this issue in public forums. | CHANGE> [Armstrong changed vote from ACCEPT to NOOP]  View
8706  CVE-2004-0278  Candidate  Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified, which causes Ratbag to repeatedly check the socket for more data.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View
8707  CVE-2004-0279  Candidate  AIM Sniff (aimSniff.pl) 0.9b allows local users to overwrite arbitrary files via a symlink attack on /tmp/AS.log.  Proposed (20040318)  NOOP(4) Armstrong, Cole, Cox, Wall    View

Page 20920 of 20943, showing 5 records out of 104715 total, starting on record 104596, ending on 104600

Actions