CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1656 | CVE-2000-0078 | Candidate | The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command. | Modified (20090302) | ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is June 1999 equivalent to HP-UX 10.x? | Prosser> The HP Bulletin (already ref"d) just specifies 10.x and 11.x OS versions running on HP9000 700/800 series. According to Tripp (bugtraq), the audio server doesn"t run on a machine without Audio Hardware (logical). So one has to assume from the bulletin that any 9000 with audio hardware that is running a 10.x or 11.x version of OS with either the 98 or 99 version of Aserver loaded will be vulnerable to either the exploit in CVE-1999-0005(the 98 version of Aserver) or CVE-2000-0078 (the 99 version)and should take appropriate action. No patches out from HP as of 10/2/2000 so either remove the program or tighten the permissions considerably. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0077. | View |
3107 | CVE-2001-0286 | Candidate | Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. | Proposed (20010404) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop | Frech> a1-server-directory-traversal(6162) | View |
1424 | CVE-1999-1444 | Candidate | genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext. | Proposed (20010912) | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech | Frech> (Task 2290) | View |
1392 | CVE-1999-1412 | Candidate | A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes. | Proposed (20010912) | NOOP(3) Cole, Foat, Wall | REVIEWING(1) Frech | Frech> (Task 2288) | View |
1380 | CVE-1999-1400 | Candidate | The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked. | Proposed (20010912) | ACCEPT(1) Wall | NOOP(2) Cole, Foat | REVIEWING(1) Frech | Frech> (Task 2287) | CONFIRM NTBUGTRAQ:19990604 Official response from The | Economist re: 1999 Screen Saver | View |
Page 241 of 20943, showing 5 records out of 104715 total, starting on record 1201, ending on 1205