CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5600  CVE-2002-1216  Candidate  GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.  Modified (20061211)  ACCEPT(4) Armstrong, Cole, Cox, Green  CHANGE> [Cox changed vote from REVIEWING to ACCEPT]  View
8592  CVE-2004-0164  Candidate  KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.  Modified (20100819)  ACCEPT(4) Armstrong, Baker, Cole, Cox | NOOP(2) Christey, Wall  CHANGE> [Cox changed vote from NOOP to ACCEPT] | Christey> REDHAT:RHSA-2004:165 | URL:http://www.redhat.com/support/errata/RHSA-2004-165.html | Christey> SCO:SCOSA-2005.10 | URL:ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.10/SCOSA-2005.10.txt  View
5785  CVE-2002-1401  Candidate  Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.  Modified (20071113)  ACCEPT(3) Armstrong, Cox, Green | NOOP(2) Christey, Cole  CHANGE> [Cox changed vote from NOOP to ACCEPT] | Christey> REDHAT:RHSA-2003:010  View
4746  CVE-2002-0354  Candidate  The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.  Proposed (20020502)  ACCEPT(3) Cole, Green, Wall | MODIFY(2) Cox, Frech | NOOP(3) Armstrong, Christey, Foat  CHANGE> [Cox changed vote from ACCEPT to MODIFY] | Cox> Mozilla 0.9.9 is also vulnerable | ADDREF: http://bugzilla.mozilla.org/show_bug.cgi?id=141061 | Christey> REDHAT:RHSA-2002:079 | Christey> BUGTRAQ:20020502 Fix for Mozilla XMLHttpRequest file disclosure vulnerability | URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0016.html | REDHAT:RHSA-2002:079 | URL:http://www.redhat.com/support/errata/RHSA-2002-079.html | CONECTIVA:CLA-2002:490 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490 | BID:4628 | URL:http://www.securityfocus.com/bid/4628 | BUGTRAQ:20020504 UPDATE (1-May-2002): Reading local files in Netscape 6 and Mozilla (GM#001-NS) | URL:http://online.securityfocus.com/archive/1/270948 | Christey> XF:mozilla-netscape-xmlhttprequest-redirect(8963) | URL:http://www.iss.net/security_center/static/8963.php | Frech> XF:mozilla-netscape-xmlhttprequest-redirect(8963)  View
3436  CVE-2001-0623  Candidate  sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.  Modified (20050309)  ACCEPT(2) Baker, Frech | NOOP(5) Bishop, Cole, Foat, Wall, Ziese | REVIEWING(1) Christey  CHANGE> [Bishop changed vote from REVIEWING to NOOP] | Christey> Need to figure out if this is one or multiple problems. | (See BIDs 2631, 2652, and 2645).  View

Page 356 of 20943, showing 5 records out of 104715 total, starting on record 1776, ending on 1780

Actions