CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3239 | CVE-2001-0421 | Candidate | FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition. | Proposed (20010524) | ACCEPT(1) Cole | MODIFY(2) Dik, Frech | NOOP(1) Wall | REVIEWING(2) Williams, Ziese | Frech> XF:solaris-ftp-shadow-recovery(6422) | Dik> sun bug ids: 4436988 | | The "world-readable" core dump problem does not exist in | Solaris 8 and other Solaris releases which have been patched | to include the "coreadm" command and possibly earlier (many release | have been patched to avoid core dumps in more situations and | always make them mode 0600) | | Solaris 8 was the first release to contain coreadm initially | (backported and include in 2.6 & 7) | Solaris 7 was the first release to make core dumps mode 0600. | (fix backported to 2.6 and earlier) | View |
3242 | CVE-2001-0424 | Candidate | BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:bubblemon-elevate-privileges(6378) | View |
3243 | CVE-2001-0425 | Candidate | AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information. | Proposed (20010524) | MODIFY(1) Frech | NOOP(4) Cole, Oliver, Wall, Ziese | Frech> XF:adcycle-adlibrarypm-unauthorized-access(6618) | View |
3244 | CVE-2001-0426 | Candidate | Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable. | Proposed (20010524) | ACCEPT(1) Dik | MODIFY(1) Frech | NOOP(2) Cole, Wall | REVIEWING(1) Ziese | Frech> XF:solaris-dtsession-bo(6366) | Dik> sun bug: 4448598 | View |
3249 | CVE-2001-0431 | Candidate | Vulnerability in iPlanet Web Server Enterprise Edition 4.x. | Proposed (20010524) | ACCEPT(3) Baker, Cole, Ziese | NOOP(1) Wall | REJECT(1) Frech | Frech> Duplicate of CVE-2001-0327. | View |
Page 292 of 20943, showing 5 records out of 104715 total, starting on record 1456, ending on 1460