CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1656  CVE-2000-0078  Candidate  The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.  Modified (20090302)  ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | REVIEWING(1) Christey  Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is June 1999 equivalent to HP-UX 10.x? | Prosser> The HP Bulletin (already ref"d) just specifies 10.x and 11.x OS versions running on HP9000 700/800 series. According to Tripp (bugtraq), the audio server doesn"t run on a machine without Audio Hardware (logical). So one has to assume from the bulletin that any 9000 with audio hardware that is running a 10.x or 11.x version of OS with either the 98 or 99 version of Aserver loaded will be vulnerable to either the exploit in CVE-1999-0005(the 98 version of Aserver) or CVE-2000-0078 (the 99 version)and should take appropriate action. No patches out from HP as of 10/2/2000 so either remove the program or tighten the permissions considerably. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0077.  View
1657  CVE-2000-0079  Candidate  The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.  Proposed (20000125)  MODIFY(2) Baker, Frech | NOOP(2) Christey, Williams | RECAST(1) LeBlanc  Frech> XF:w3c-httpd-reveal-paths | LeBlanc> Title references IIS, vuln references W3C CERN httpd. Which | one is broken? | Christey> The mention of CERN httpd was buried in a followup on a | description of an IIS problem, so this is the correct reference. | Baker> Will the XF reference be added?  View
1658  CVE-2000-0080  Entry  AIX techlibss allows local users to overwrite files via a symlink attack.        View
1659  CVE-2000-0081  Candidate  Hotmail does not properly filter JavaScript code from a user"s mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. jAvascript.  Proposed (20000125)  MODIFY(1) Frech | REJECT(1) Baker  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:hotmail-vascript-java-injection  View
1660  CVE-2000-0082  Candidate  WebTV email client allows remote attackers to force the client to send email without the user"s knowledge via HTML.  Modified (20040901)  MODIFY(1) Frech | REJECT(1) Baker  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> ADDREF XF:webtv-hijack-mail-forward  View

Page 332 of 20943, showing 5 records out of 104715 total, starting on record 1656, ending on 1660

Actions