CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
242 | CVE-1999-0243 | Candidate | Linux cfingerd could be exploited to gain root access. | Proposed (19990714) | ACCEPT(1) Shostack | NOOP(4) Baker, Levy, Northcutt, Wall | REJECT(2) Christey, Frech | Christey> This has no sources; neither does the original database that | this entry came from. It"s a likely duplicate of | CVE-1999-0813. | Frech> I disagree on the dupe; see Linux-Security Mailing List, | "[linux-security] Cfinger (Yet more :)" at | http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as | if v1.2.3 is vulnerable, perhaps 1.3.0 also. CVE-1999-0813 pertains | to 1.4.x and below and shows up two years later. | CHANGE> [Frech changed vote from REVIEWING to REJECT] | Frech> If the reference I previously supplied is correct, then | it appears as if the poster modified the source using authorized | access to make it vulnerable. Modifying the source in this manner | does not qualify as being listed a vulnerability. | I disagree on the dupe; see Linux-Security Mailing List, | "[linux-security] Cfinger (Yet more :)" at | http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as | if v1.2.3 is vulnerable, perhaps 1.3.0 also. CVE-1999-0813 pertains | to 1.4.x and below and shows up two years later. | View |
78 | CVE-1999-0078 | Candidate | pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. | Modified (19990621-01) | ACCEPT(5) Collins, Frech, Landfield, Northcutt, Shostack | NOOP(1) Baker | RECAST(1) Christey | Christey> This candidate should be SPLIT, since there are two separate | software flaws. One is a symlink race and the other is a | shell metacharacter problem. | Christey> The permissions part of this vulnerability appears to | overlap with CVE-1999-0353 | Christey> SGI:20020802-01-I | View |
796 | CVE-1999-0816 | Candidate | The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024. | Modified (20000313-01) | ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(2) Christey, LeBlanc | Christey> This candidate is unconfirmed by the vendor. | Frech> XF:motorola-cable-default-pass | View |
899 | CVE-1999-0919 | Candidate | A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections. | Modified (20020226-02) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(7) Armstrong, Christey, Landfield, LeBlanc, Ozancin, Stracener, Wall | REVIEWING(1) Levy | Christey> This candidate is unconfirmed by the vendor. | Frech> XF:motorola-cable-crash | Christey> This has enough votes, but not the "confidence" yet (until we | resolve the question of the amount of verification needed | for CVE). | View |
865 | CVE-1999-0885 | Candidate | Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL. | Modified (20000313-01) | ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(5) Armstrong, Blake, Christey, Cole, LeBlanc | Christey> This candidate is unconfirmed by the vendor. | Blake> Same as CVE-1999-0776. | Frech> XF:alibaba-url-file-manipulation | Christey> CD:SF-LOC and CD:SF-EXEC may say to merge this candidate with | the problems described in: | BUGTRAQ:20000718 Multiple bugs in Alibaba 2.0 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html | | If so, then ADDREF BID:1485 as well. | Christey> Include the names of the affected CGI"s, including tst.bat, | get32.exe, alibaba.pl, etc. | View |
Page 283 of 20943, showing 5 records out of 104715 total, starting on record 1411, ending on 1415