CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
166 | CVE-1999-0166 | Entry | NFS allows users to use a "cd .." command to access other directories besides the exported file system. | View | |||
167 | CVE-1999-0167 | Entry | In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system. | View | |||
168 | CVE-1999-0168 | Entry | The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions. | View | |||
169 | CVE-1999-0169 | Candidate | NFS allows attackers to read and write any file on the system by specifying a false UID. | Proposed (19990714) | ACCEPT(2) Frech, Northcutt | MODIFY(1) Baker | REJECT(1) Shostack | Shostack> this is not a vulnerability but a design feature. | Baker> Maybe we should reword it so that it is clear that this was a problem to something like: | | "A remote attacker could read/write files to the system with root-level permissions on NFS servers that fail to properly check the UID." | View |
170 | CVE-1999-0170 | Entry | Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. | View |
Page 34 of 20943, showing 5 records out of 104715 total, starting on record 166, ending on 170