CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7847 | CVE-2003-1023 | Candidate | Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion. | Assigned (20040105) | NOOP(1) Christey | Christey> CALDERA:CSSA-2004-014.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-014.0.txt | View |
5665 | CVE-2002-1281 | Candidate | Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote attackers to execute arbitrary code via a certain URL. | Modified (20071129) | ACCEPT(4) Armstrong, Cole, Cox, Green | NOOP(1) Christey | Christey> CALDERA:CSSA-2003-012.0 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-012.0.txt | View |
5666 | CVE-2002-1282 | Candidate | Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL. | Modified (20071129) | ACCEPT(4) Armstrong, Cole, Cox, Green | NOOP(1) Christey | Christey> CALDERA:CSSA-2003-012.0 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-012.0.txt | View |
4499 | CVE-2002-0105 | Candidate | CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable. | Proposed (20020315) | ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey | Christey> CALDERA:CSSA-2002-SCO.18 | XF:cde-dt-world-writable(9045) | URL:http://www.iss.net/security_center/static/9045.php | Note: the advisory sort-of implies that world-write | permissions were the key problem, so the fact that a symlink | attack could take place did not necessarily mean that a | symlink following vulnerability really existed, in the sense | that symlink attacks don"t exist in directories that are | not writable by other users (well, without those users | exploiting some *other* vulnerability to allow them to create | the symlink!) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Hmmm... should XF:cde-dt-world-writable(9045) really be added | here? ISS may have "split" between the permissions issue | and the symlink problem. | View |
4916 | CVE-2002-0525 | Candidate | Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses. | Proposed (20020611) | ACCEPT(3) Cole, Cox, Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey | Christey> CALDERA:CSSA-2002-038.0 | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Need to consult with Caldera on this. | View |
Page 324 of 20943, showing 5 records out of 104715 total, starting on record 1616, ending on 1620