CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3844  CVE-2001-1040  Candidate  HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.  Proposed (20020131)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall  Frech> Not jetdirect-jetadmin-telnet-access(6950). | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:jetdirect-admin-password-reset(8713)  View
1489  CVE-1999-1509  Candidate  Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.  Proposed (20010912)  ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall  Frech> Normalize XF:eserv-fileread(3449) | Normalize URL:http://xforce.iss.net/static/3449.php  View
410  CVE-1999-0411  Candidate  Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access.  Proposed (19990726)  MODIFY(2) Baker, Frech | NOOP(2) Christey, Wall  Frech> Neither XFDB nor the BugTraq article (incidentally, shows up as 7 March, not | 19 February) does not mention gaining root access... it says a local user | could | "delete or overwrite arbitrary files on the system." | Baker> By overwriting arbitrary files, one could then gain root access. I agree with a minor description change to reflect this. | Christey> Normalize Bugtraq reference to: | BUGTRAQ:19990307 Little exploit for startup scripts (SCO 5.0.4p). | http://marc.theaimsgroup.com/?l=bugtraq&m=92087765014242&w=2 | Also, SCO:SB-99.17 | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.17c  View
3369  CVE-2001-0556  Candidate  The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users" files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.  Proposed (20010727)  ACCEPT(6) Baker, Bishop, Cole, Foat, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Christey, Wall  Frech> nedit-print-symlink(6424) | Christey> SGI:20011105-01-P | ftp://patches.sgi.com/support/free/security/advisories/20011105-01-P | ADDREF BID:2627 | URL:http://www.securityfocus.com/bid/2627 | (there are different BID"s for the different symlink issues)  View
451  CVE-1999-0452  Candidate  A service or application has a backdoor password that was placed there by the developer.  Proposed (19990726)  ACCEPT(2) Baker, Wall | REJECT(1) Frech  Frech> Much too broad. Also may be HIGHCARD (or will be in the future). | Baker> I think we want to address this using the dot notation idea. We do need to address this, just not a separate entry for every single occurance.  View

Page 226 of 20943, showing 5 records out of 104715 total, starting on record 1126, ending on 1130

Actions