CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2299  CVE-2000-0723  Candidate  Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:gnome-installer-overwrite-configuration(5129) | Frech> XF:gnome-installer-overwrite-configuration(5129)  View
2300  CVE-2000-0724  Candidate  The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.  Proposed (20000921)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) Christey, Wall  Christey> XF:go-gnome-preinstaller-symlink(5161) | Frech> XF:go-gnome-preinstaller-symlink(5161)  View
2199  CVE-2000-0623  Candidate  Buffer overflow in O"Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.  Proposed (20000803)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) LeBlanc | REVIEWING(1) Wall  Frech> XF:website-httpd32-bo(4970) | In the description, I think it"s spelled "referer"  View
2201  CVE-2000-0625  Candidate  NetZero 3.0 and earlier uses weak encryption for storing a user"s login information, which allows a local user to decrypt the password.  Proposed (20000803)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(2) LeBlanc, Wall  Frech> XF:zeroport-weak-encryption(4963)  View
2202  CVE-2000-0626  Candidate  Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.  Proposed (20000803)  ACCEPT(4) Baker, Blake, Levy, Wall | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, LeBlanc, Oliver, Ozancin | REVIEWING(1) Christey  Frech> XF:alibaba-get-dos(4934) | Christey> This is in a relatively old Nessus plugin, though the exploit | uses POST instead of GET. This was probably discovered | earlier than the references indicate. | CHANGE> [Wall changed vote from NOOP to ACCEPT] | Wall> Found by Arne Vidstrom and found in multiple sources | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> See the POST comment in | http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2 | Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2 | | One poster says that a large number of sites are running | Alibaba (based on a netcraft report), but I"m not 100% | sure Netcraft"s doing a good job of identifying Alibaba | servers.  View

Page 351 of 20943, showing 5 records out of 104715 total, starting on record 1751, ending on 1755

Actions