CVE List

Id CVE No. Status Description Phase Votes Comments Actions
242  CVE-1999-0243  Candidate  Linux cfingerd could be exploited to gain root access.  Proposed (19990714)  ACCEPT(1) Shostack | NOOP(4) Baker, Levy, Northcutt, Wall | REJECT(2) Christey, Frech  Christey> This has no sources; neither does the original database that | this entry came from. It"s a likely duplicate of | CVE-1999-0813. | Frech> I disagree on the dupe; see Linux-Security Mailing List, | "[linux-security] Cfinger (Yet more :)" at | http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as | if v1.2.3 is vulnerable, perhaps 1.3.0 also. CVE-1999-0813 pertains | to 1.4.x and below and shows up two years later. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> If the reference I previously supplied is correct, then | it appears as if the poster modified the source using authorized | access to make it vulnerable. Modifying the source in this manner | does not qualify as being listed a vulnerability. | I disagree on the dupe; see Linux-Security Mailing List, | "[linux-security] Cfinger (Yet more :)" at | http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as | if v1.2.3 is vulnerable, perhaps 1.3.0 also. CVE-1999-0813 pertains | to 1.4.x and below and shows up two years later.  View
78  CVE-1999-0078  Candidate  pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.  Modified (19990621-01)  ACCEPT(5) Collins, Frech, Landfield, Northcutt, Shostack | NOOP(1) Baker | RECAST(1) Christey  Christey> This candidate should be SPLIT, since there are two separate | software flaws. One is a symlink race and the other is a | shell metacharacter problem. | Christey> The permissions part of this vulnerability appears to | overlap with CVE-1999-0353 | Christey> SGI:20020802-01-I  View
796  CVE-1999-0816  Candidate  The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.  Modified (20000313-01)  ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(2) Christey, LeBlanc  Christey> This candidate is unconfirmed by the vendor. | Frech> XF:motorola-cable-default-pass  View
899  CVE-1999-0919  Candidate  A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.  Modified (20020226-02)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(7) Armstrong, Christey, Landfield, LeBlanc, Ozancin, Stracener, Wall | REVIEWING(1) Levy  Christey> This candidate is unconfirmed by the vendor. | Frech> XF:motorola-cable-crash | Christey> This has enough votes, but not the "confidence" yet (until we | resolve the question of the amount of verification needed | for CVE).  View
865  CVE-1999-0885  Candidate  Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.  Modified (20000313-01)  ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(5) Armstrong, Blake, Christey, Cole, LeBlanc  Christey> This candidate is unconfirmed by the vendor. | Blake> Same as CVE-1999-0776. | Frech> XF:alibaba-url-file-manipulation | Christey> CD:SF-LOC and CD:SF-EXEC may say to merge this candidate with | the problems described in: | BUGTRAQ:20000718 Multiple bugs in Alibaba 2.0 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html | | If so, then ADDREF BID:1485 as well. | Christey> Include the names of the affected CGI"s, including tst.bat, | get32.exe, alibaba.pl, etc.  View

Page 283 of 20943, showing 5 records out of 104715 total, starting on record 1411, ending on 1415

Actions