CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
798 | CVE-1999-0818 | Candidate | Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. | Proposed (19991208) | ACCEPT(2) Armstrong, Stracener | MODIFY(4) Cole, Dik, Frech, Prosser | NOOP(1) Baker | REVIEWING(1) Christey | Cole> This can cause code to be executed. | Frech> XF:sol-kcms-conf-netpath-bo | Dik> the bug has nothing to do with kcms_configure; it"s a bug | in libnsl.so. All set-uid executables that trigger this code path are | vulnerable. Sun bug 4295834; fixed in Solaris 8. | Prosser> Okay, I am confused. Based on Casper"s comments and checking | on the Sun patch site, I found the 4295834 bug(4295834 NETPATH security | problem in libnsl) fixed in SunOS 5.4, Patch 101974-37(x86) 101973 (sparc). | Multiple libnsl vulnerabilities was first reported in an 98 Sun Bulletin | #00172 for 5.4 up through 2.6. Was this NETPATH a problem that resurfaced | in 7 (looks like in 5.4 as well) and was fixed in 8? | Christey> Need to dig up my offline email on this. | Christey> May be a duplicate of CVE-1999-0321, whose sole reference | (XF:sun-kcms-configure-bo) no longer exists. Also examine | BID:452 and | BUGTRAQ:19981223 Merry Christmas to Sun! (Was: L0pht NFR N-Code | Modules Updated) | | which are the same as XF:sol-kcms-conf-p-bo(3652), which could | be the new name for XF:sun-kcms-configure-bo. | View |
807 | CVE-1999-0827 | Candidate | By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. | Proposed (19991208) | ACCEPT(4) Armstrong, Baker, LeBlanc, Stracener | MODIFY(2) Cole, Frech | REVIEWING(1) Prosser | Cole> The BID is 855. If I have the right vulnerability, this allows an | attacker to access URL"s of there choosing which could lead to a compromise | of private information. | Frech> XF:http-frame-spoof | Question: Similar vulnerability to MS98-020 / CVE-1999-0869? | LeBlanc> MSRC tells me this is patched in MS00-009 | View |
835 | CVE-1999-0855 | Candidate | Buffer overflow in FreeBSD gdc program. | Proposed (19991208) | ACCEPT(3) Armstrong, Prosser, Stracener | MODIFY(2) Cole, Frech | NOOP(2) Baker, Christey | Cole> The BID is 834 and the reference is 19991201 not 1130. | Frech> XF:freebsd-gdc-bo | Christey> ADDREF BID:780 ? | View |
1702 | CVE-2000-0124 | Candidate | surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions. | Proposed (20000208) | MODIFY(2) Baker, Frech | NOOP(2) Christey, Wall | RECAST(1) Cole | Cole> See comments for CVE-2000-0101 | Frech> XF:surfcontrol-superscout-bypass-filter(4009) | Christey> Fix typo: "asign" | Baker> Description still has typo asign instead of assign | View |
1680 | CVE-2000-0102 | Candidate | The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | Proposed (20000208) | ACCEPT(1) Baker | MODIFY(1) Frech | RECAST(1) Cole | REVIEWING(1) Wall | Cole> See comments for CVE-2000-0101 | Frech> XF:shopping-cart-form-tampering | View |
Page 260 of 20943, showing 5 records out of 104715 total, starting on record 1296, ending on 1300