CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
405 | CVE-1999-0406 | Candidate | Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege. | Proposed (19990728) | ACCEPT(1) Baker | MODIFY(1) Frech | Frech> In description, change "which" to "that". | View |
2872 | CVE-2001-0051 | Candidate | IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the databasse. | Proposed (20010202) | ACCEPT(2) Baker, Frech | NOOP(3) Cole, Wall, Ziese | Frech> In description, "database", not "databasse". | View |
3805 | CVE-2001-1000 | Candidate | rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file. | Proposed (20020131) | ACCEPT(1) Frech | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Green | Frech> If the software is available to the general public, then it | should | be included in CVE. Marking the software "MichNet Only" does not | prevent | someone from running it outside of MichNet, but it allegedly may | protect | MichNet against actual or perceived liabilities. | View |
393 | CVE-1999-0394 | Candidate | DPEC Online Courseware allows an attacker to change another user"s password without knowing the original password. | Proposed (19990728) | ACCEPT(1) Baker | NOOP(1) Christey | REJECT(1) Frech | Frech> If I understand the issue, this HIGHCARD involves insecure web programming. | If I don"t understand, mark this as my first NOOP. | Christey> CONFIRM:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19990803132618.16407.qmail%40securityfocus.com | ADDREF BID:565 | URL:http://www.securityfocus.com/vdb/bottom.html?vid=565 | View |
1049 | CVE-1999-1069 | Candidate | Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter. | Proposed (20010912) | ACCEPT(2) Cole, Frech | NOOP(1) Foat | Frech> iCat"s site at http://www.icat.com/ is shut down, and no | further support seems to be available. | View |
Page 228 of 20943, showing 5 records out of 104715 total, starting on record 1136, ending on 1140