CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2473  CVE-2000-0904  Candidate  Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.  Proposed (20001129)  ACCEPT(1) Mell | NOOP(3) Cole, Collins, Wall  Collins> assigning CVE numbers for demo software is not appropriate  View
837  CVE-1999-0857  Candidate  FreeBSD gdc program allows local users to modify files via a symlink attack.  Proposed (19991208)  ACCEPT(3) Armstrong, Prosser, Stracener | MODIFY(2) Cole, Frech | NOOP(1) Baker  Cole> This is via debug output. | Frech> XF:freebsd-gdc  View
840  CVE-1999-0860  Candidate  Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.  Proposed (19991208)  ACCEPT(2) Armstrong, Stracener | MODIFY(2) Dik, Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | REVIEWING(1) Prosser  Cole> This is the same as the pervious. | Frech> XF:sol-chkperm-vmsys | Dik> include reference to Sun bug 4296167 | Christey> Remove BID:837, which is for arp, not chkperm  View
808  CVE-1999-0828  Candidate  UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.  Modified (20000121-01)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Cole, Frech | REVIEWING(2) Christey, Prosser  Cole> This is BID 850. | Christey> See comments on CVE-1999-0988. Perhaps these two should be | merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a | loosely alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:sco-pkg-dacread-fileread  View
810  CVE-1999-0830  Candidate  Buffer overflow in SCO UnixWare Xsco command via a long argument.  Proposed (19991208)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(3) Cole, Frech, Prosser | REVIEWING(1) Christey  Cole> This is BID 824 and the BUGTRAQ reference is 19991125. | Frech> XF:sco-unixware-xsco | Christey> Confirmed by vendor, albeit vaguely: | http://marc.theaimsgroup.com/?l=bugtraq&m=94581379905584&w=2 | | Prosser> agree with Steve on vendor confirmation, however not sure the | fix ref"d in BID 824 (SSE041) is right. It lists fixes for libnsl and | tcpip.so, nothing about xsco. SSE050b | (ftp://ftp.sco.com/SSE/security_bulletins/SB-99.26b) fixes a buffer overflow | in xsco on OpenServer (the vendor message Steve refers to) but not the | UnixWare vulnerability reported on Bugtraq and in BID824. Anyone more | familar with SCO shed some light on this? Are they the same codebase so fix | would be same? From the SCO site it seems the UnixWare and OpenSever | products are similar but have differences. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:824 | http://www.securityfocus.com/bid/824  View

Page 259 of 20943, showing 5 records out of 104715 total, starting on record 1291, ending on 1295

Actions