CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1656  CVE-2000-0078  Candidate  The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.  Modified (20090302)  ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is June 1999 equivalent to HP-UX 10.x? | Prosser> The HP Bulletin (already ref"d) just specifies 10.x and 11.x OS versions running on HP9000 700/800 series. According to Tripp (bugtraq), the audio server doesn"t run on a machine without Audio Hardware (logical). So one has to assume from the bulletin that any 9000 with audio hardware that is running a 10.x or 11.x version of OS with either the 98 or 99 version of Aserver loaded will be vulnerable to either the exploit in CVE-1999-0005(the 98 version of Aserver) or CVE-2000-0078 (the 99 version)and should take appropriate action. No patches out from HP as of 10/2/2000 so either remove the program or tighten the permissions considerably. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0077.  View
3107  CVE-2001-0286  Candidate  Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.  Proposed (20010404)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> a1-server-directory-traversal(6162)  View
1424  CVE-1999-1444  Candidate  genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.  Proposed (20010912)  NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech  Frech> (Task 2290)  View
1392  CVE-1999-1412  Candidate  A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.  Proposed (20010912)  NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech  Frech> (Task 2288)  View
1380  CVE-1999-1400  Candidate  The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.  Proposed (20010912)  ACCEPT(1) Wall | NOOP(2) Cole, Foat | REVIEWING(1) Frech  Frech> (Task 2287) | CONFIRM NTBUGTRAQ:19990604 Official response from The | Economist re: 1999 Screen Saver  View

Page 241 of 20943, showing 5 records out of 104715 total, starting on record 1201, ending on 1205

Actions