CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1266  CVE-1999-1286  Candidate  addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.  Modified (20060623)  ACCEPT(1) Frech | NOOP(3) Christey, Cole, Foat  Christey> CHANGE DESC: "via a symlink attack on the printers temporary file." | Add 5.3 as another affected version. | | MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX | SGI:19961203-02-PX may solve this problem, but the advisory is so | vague that it is uncertain whether this was fixed or not. addnetpr is | not specifically named in the advisory, which names netprint, which is | not specified in the original Bugtraq post. In addition, the date on | the advisory is one day earlier than that of the Bugtraq post, though | that could be a difference in time zones. It seems plausible that the | problem had already been patched (the researcher did say "There *was* | [a] race condition") so maybe SGI released this advisory after the | problem was publicized. | | ADDREF BID:330 | URL:http://www.securityfocus.com/bid/330 | | Note: this is a dupe of CVE-1999-1410, but CVE-1999-1410 will | be rejected in favor of CVE-1999-1286.  View
1267  CVE-1999-1287  Candidate  Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.  Proposed (20010912)  ACCEPT(4) Armstrong, Cole, Frech, Stracener | NOOP(2) Foat, Wall  CHANGE> [Foat changed vote from ACCEPT to NOOP]  View
1268  CVE-1999-1288  Entry  Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.        View
1269  CVE-1999-1289  Candidate  ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.  Proposed (20010912)  ACCEPT(3) Cole, Frech, Wall | NOOP(1) Foat  Frech> Override EX-BETA in this case, since ICQ is always in beta | and is | widely run in production environments.  View
1270  CVE-1999-1290  Entry  Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.        View

Page 254 of 20943, showing 5 records out of 104715 total, starting on record 1266, ending on 1270

Actions