CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2473 | CVE-2000-0904 | Candidate | Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information. | Proposed (20001129) | ACCEPT(1) Mell | NOOP(3) Cole, Collins, Wall | Collins> assigning CVE numbers for demo software is not appropriate | View |
837 | CVE-1999-0857 | Candidate | FreeBSD gdc program allows local users to modify files via a symlink attack. | Proposed (19991208) | ACCEPT(3) Armstrong, Prosser, Stracener | MODIFY(2) Cole, Frech | NOOP(1) Baker | Cole> This is via debug output. | Frech> XF:freebsd-gdc | View |
840 | CVE-1999-0860 | Candidate | Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack. | Proposed (19991208) | ACCEPT(2) Armstrong, Stracener | MODIFY(2) Dik, Frech | NOOP(2) Baker, Christey | REJECT(1) Cole | REVIEWING(1) Prosser | Cole> This is the same as the pervious. | Frech> XF:sol-chkperm-vmsys | Dik> include reference to Sun bug 4296167 | Christey> Remove BID:837, which is for arp, not chkperm | View |
808 | CVE-1999-0828 | Candidate | UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission. | Modified (20000121-01) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Cole, Frech | REVIEWING(2) Christey, Prosser | Cole> This is BID 850. | Christey> See comments on CVE-1999-0988. Perhaps these two should be | merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a | loosely alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:sco-pkg-dacread-fileread | View |
810 | CVE-1999-0830 | Candidate | Buffer overflow in SCO UnixWare Xsco command via a long argument. | Proposed (19991208) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(3) Cole, Frech, Prosser | REVIEWING(1) Christey | Cole> This is BID 824 and the BUGTRAQ reference is 19991125. | Frech> XF:sco-unixware-xsco | Christey> Confirmed by vendor, albeit vaguely: | http://marc.theaimsgroup.com/?l=bugtraq&m=94581379905584&w=2 | | Prosser> agree with Steve on vendor confirmation, however not sure the | fix ref"d in BID 824 (SSE041) is right. It lists fixes for libnsl and | tcpip.so, nothing about xsco. SSE050b | (ftp://ftp.sco.com/SSE/security_bulletins/SB-99.26b) fixes a buffer overflow | in xsco on OpenServer (the vendor message Steve refers to) but not the | UnixWare vulnerability reported on Bugtraq and in BID824. Anyone more | familar with SCO shed some light on this? Are they the same codebase so fix | would be same? From the SCO site it seems the UnixWare and OpenSever | products are similar but have differences. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:824 | http://www.securityfocus.com/bid/824 | View |
Page 259 of 20943, showing 5 records out of 104715 total, starting on record 1291, ending on 1295