CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4961  CVE-2002-0570  Candidate  The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.  Proposed (20020611)  ACCEPT(3) Alderson, Cole, Frech | MODIFY(1) Foat | NOOP(2) Cox, Wall  Foat> A local user can not modify the data. The user needs to root the box | first or at least get UNIX permission to write to the encrypted file system. | This is different than being a local user. | CHANGE> [Cox changed vote from REVIEWING to NOOP]  View
1895  CVE-2000-0317  Candidate  Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.  Proposed (20000518)  ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(3) Christey, LeBlanc, Wall | RECAST(1) Dik  Dik> there"s a lot of confusion in this one. | These point to buffer overflows: | Reference: BUGTRAQ:20000424 Solaris 7 x86 lpset exploit. | Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0192.html | Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0236.html | But these point to dlopen() in libprint that doesnt" check pathnames: | Reference: BUGTRAQ:20000427 Re: Solaris/SPARC 2.7 lpset exploit (well not likely !) | Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95729763119559&w=2 | Reference: SUNBUG:4334568 | And this is a bufferoverflow again: | Reference: BID:1138 | Reference: URL:http://www.securityfocus.com/bid/1138 | Frech> XF:solaris-lpset-bo | Christey> ADDREF SUN:00195? Need to check with Casper.  View
3880  CVE-2001-1076  Candidate  Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.  Modified (20061101)  ACCEPT(2) Frech, Green | MODIFY(1) Dik | NOOP(3) Armstrong, Cole, Foat | REVIEWING(1) Wall  Dik> Sun bug: 4477380 | Description errors: CFIME -> CFTIME | Don"t understand "SOR" environment variable. This must | presumably be TZ  View
3287  CVE-2001-0470  Candidate  Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.  Proposed (20010524)  ACCEPT(2) Dik, Frech | NOOP(4) Cole, Oliver, Wall, Ziese  Dik> sun bug: 4425460  View
3219  CVE-2001-0401  Candidate  Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.  Modified (20090716)  ACCEPT(2) Dik, Frech | NOOP(3) Cole, Wall, Ziese  Dik> sun bug: 4330475  View

Page 248 of 20943, showing 5 records out of 104715 total, starting on record 1236, ending on 1240

Actions