CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1393 | CVE-1999-1413 | Candidate | Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg. | Proposed (20010912) | MODIFY(2) Dik, Frech | NOOP(2) Cole, Foat | Frech> XF:solaris-coredump-symlink(7196) | Dik> sun bug: 1208241 | | Also applies to set-uid executables that have made real | and effective uid identical | View |
1138 | CVE-1999-1158 | Candidate | Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd. | Proposed (20010912) | ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | RECAST(1) Christey | Frech> XF:solaris-pam-bo(7432) | Dik> sun bug: 4018347 | Christey> These issues should be SPLIT per CD:SF-EXEC because the PAM | problem appears in different Solaris versions than | unix_scheme. | View |
1395 | CVE-1999-1415 | Candidate | Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges. | Proposed (20010912) | ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(2) Christey, Wall | Frech> XF:bsd-binmail(515) | CA-1991-13 was superseded by CA-1995-02. | Christey> Is there overlap between CVE-1999-1415 and CVE-1999-1438? | Both CERT advisories are vague. | View |
1396 | CVE-1999-1416 | Candidate | AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length. | Proposed (20010912) | NOOP(3) Cole, Foat, Wall | View | |
1397 | CVE-1999-1417 | Candidate | Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged. | Proposed (20010912) | ACCEPT(1) Dik | NOOP(3) Cole, Foat, Wall | Dik> sun bug: 4218283 | View |
Page 227 of 20943, showing 5 records out of 104715 total, starting on record 1131, ending on 1135