CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3844 | CVE-2001-1040 | Candidate | HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password. | Proposed (20020131) | ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | Frech> Not jetdirect-jetadmin-telnet-access(6950). | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:jetdirect-admin-password-reset(8713) | View |
1489 | CVE-1999-1509 | Candidate | Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL. | Proposed (20010912) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | Frech> Normalize XF:eserv-fileread(3449) | Normalize URL:http://xforce.iss.net/static/3449.php | View |
410 | CVE-1999-0411 | Candidate | Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access. | Proposed (19990726) | MODIFY(2) Baker, Frech | NOOP(2) Christey, Wall | Frech> Neither XFDB nor the BugTraq article (incidentally, shows up as 7 March, not | 19 February) does not mention gaining root access... it says a local user | could | "delete or overwrite arbitrary files on the system." | Baker> By overwriting arbitrary files, one could then gain root access. I agree with a minor description change to reflect this. | Christey> Normalize Bugtraq reference to: | BUGTRAQ:19990307 Little exploit for startup scripts (SCO 5.0.4p). | http://marc.theaimsgroup.com/?l=bugtraq&m=92087765014242&w=2 | Also, SCO:SB-99.17 | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.17c | View |
3369 | CVE-2001-0556 | Candidate | The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users" files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file. | Proposed (20010727) | ACCEPT(6) Baker, Bishop, Cole, Foat, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> nedit-print-symlink(6424) | Christey> SGI:20011105-01-P | ftp://patches.sgi.com/support/free/security/advisories/20011105-01-P | ADDREF BID:2627 | URL:http://www.securityfocus.com/bid/2627 | (there are different BID"s for the different symlink issues) | View |
451 | CVE-1999-0452 | Candidate | A service or application has a backdoor password that was placed there by the developer. | Proposed (19990726) | ACCEPT(2) Baker, Wall | REJECT(1) Frech | Frech> Much too broad. Also may be HIGHCARD (or will be in the future). | Baker> I think we want to address this using the dot notation idea. We do need to address this, just not a separate entry for every single occurance. | View |
Page 226 of 20943, showing 5 records out of 104715 total, starting on record 1126, ending on 1130