CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1266 | CVE-1999-1286 | Candidate | addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file. | Modified (20060623) | ACCEPT(1) Frech | NOOP(3) Christey, Cole, Foat | Christey> CHANGE DESC: "via a symlink attack on the printers temporary file." | Add 5.3 as another affected version. | | MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX | SGI:19961203-02-PX may solve this problem, but the advisory is so | vague that it is uncertain whether this was fixed or not. addnetpr is | not specifically named in the advisory, which names netprint, which is | not specified in the original Bugtraq post. In addition, the date on | the advisory is one day earlier than that of the Bugtraq post, though | that could be a difference in time zones. It seems plausible that the | problem had already been patched (the researcher did say "There *was* | [a] race condition") so maybe SGI released this advisory after the | problem was publicized. | | ADDREF BID:330 | URL:http://www.securityfocus.com/bid/330 | | Note: this is a dupe of CVE-1999-1410, but CVE-1999-1410 will | be rejected in favor of CVE-1999-1286. | View |
1267 | CVE-1999-1287 | Candidate | Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface. | Proposed (20010912) | ACCEPT(4) Armstrong, Cole, Frech, Stracener | NOOP(2) Foat, Wall | CHANGE> [Foat changed vote from ACCEPT to NOOP] | View |
1268 | CVE-1999-1288 | Entry | Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program. | View | |||
1269 | CVE-1999-1289 | Candidate | ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration. | Proposed (20010912) | ACCEPT(3) Cole, Frech, Wall | NOOP(1) Foat | Frech> Override EX-BETA in this case, since ICQ is always in beta | and is | widely run in production environments. | View |
1270 | CVE-1999-1290 | Entry | Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string. | View |
Page 254 of 20943, showing 5 records out of 104715 total, starting on record 1266, ending on 1270