CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7847  CVE-2003-1023  Candidate  Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.  Assigned (20040105)  NOOP(1) Christey  Christey> CALDERA:CSSA-2004-014.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2004-014.0.txt  View
5665  CVE-2002-1281  Candidate  Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote attackers to execute arbitrary code via a certain URL.  Modified (20071129)  ACCEPT(4) Armstrong, Cole, Cox, Green | NOOP(1) Christey  Christey> CALDERA:CSSA-2003-012.0 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-012.0.txt  View
5666  CVE-2002-1282  Candidate  Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary code via a certain URL.  Modified (20071129)  ACCEPT(4) Armstrong, Cole, Cox, Green | NOOP(1) Christey  Christey> CALDERA:CSSA-2003-012.0 | URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-012.0.txt  View
4499  CVE-2002-0105  Candidate  CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable.  Proposed (20020315)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Christey  Christey> CALDERA:CSSA-2002-SCO.18 | XF:cde-dt-world-writable(9045) | URL:http://www.iss.net/security_center/static/9045.php | Note: the advisory sort-of implies that world-write | permissions were the key problem, so the fact that a symlink | attack could take place did not necessarily mean that a | symlink following vulnerability really existed, in the sense | that symlink attacks don"t exist in directories that are | not writable by other users (well, without those users | exploiting some *other* vulnerability to allow them to create | the symlink!) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Hmmm... should XF:cde-dt-world-writable(9045) really be added | here? ISS may have "split" between the permissions issue | and the symlink problem.  View
4916  CVE-2002-0525  Candidate  Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.  Proposed (20020611)  ACCEPT(3) Cole, Cox, Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey  Christey> CALDERA:CSSA-2002-038.0 | CHANGE> [Cox changed vote from REVIEWING to ACCEPT] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> Need to consult with Caldera on this.  View

Page 324 of 20943, showing 5 records out of 104715 total, starting on record 1616, ending on 1620

Actions