CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3391 | CVE-2001-0578 | Candidate | Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command. | Modified (20020225-01) | ACCEPT(2) Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker | Bishop> recommend combining as stated in analysis | Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem. | View |
3392 | CVE-2001-0579 | Candidate | lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command. | Proposed (20010727) | ACCEPT(2) Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker | Bishop> recommend combining as stated in analysis | Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem. | View |
3388 | CVE-2001-0575 | Candidate | Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut. | Modified (20020225-01) | ACCEPT(3) Baker, Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese | Bishop> recommend combining as stated in analysis | Baker> http://support.caldera.com/caldera/solution?11=113723&130=0988647911&14=&2715=&15=&2716=&57=search&58=&2900=dckSSu3pru&25=6&3=SSE072B | "What is SSE072B, the buffer overflow security patch for Openserver 5? (Ref. #113723)" | Buffer overflows have been found in the following 19 | SCO OpenServer 5 utilities: | | /usr/bin/accept | /usr/bin/cancel | /usr/mmdf/bin/deliver | /usr/bin/disable | /usr/bin/enable | /usr/lib/libcurses.a | /usr/bin/lp | /usr/lib/lpadmin | /usr/lib/lpfilter | /usr/lib/lpforms | /usr/lib/lpmove | /usr/lib/lpshut | /usr/bin/lpstat | /usr/lib/lpusers | /usr/bin/recon | /usr/bin/reject | /usr/bin/rmail | /usr/lib/sendmail | /usr/bin/tput | | NOTE: the accept, reject, enable, and disable commands are | symbolically linked to the same binary. | | Running any of the above utilities with a very large argument | can result in a core dump. | View |
3449 | CVE-2001-0636 | Candidate | Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing long passwords, or (2) execute arbitrary commands via long HTTP queries in the Knowledge Browser component in SilentRunner 2.0 and 2.0.1. NOTE: It is highly likely that this candidate will be split into multiple candidates. | Proposed (20010829) | ACCEPT(3) Cole, Foat, Ziese | MODIFY(1) Frech | NOOP(3) Armstrong, Christey, Wall | RECAST(2) Baker, Bishop | Bishop> please split it into 2 candidates, one for the DoS and one | for the execute part | Frech> XF:silentrunner-collector-popuser-bo(6795) | XF:silentrunner-collector-poppass-bo(6796) | XF:silentrunner-collector-httpurl-bo(6797) | Baker> SPLIT | Christey> Consider adding BID:3150 | Christey> Consider adding BID:3151 | View |
3379 | CVE-2001-0566 | Candidate | Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled. | Proposed (20010727) | ACCEPT(3) Baker, Frech, Ziese | MODIFY(1) Bishop | NOOP(2) Cole, Wall | REJECT(1) Foat | Bishop> Is the entire switch shut down or is traffic blocked for a | limited time? | Foat> Unable to duplicate event | Baker> Seems kind of strange that someone that works at Cisco would accept this vulnerability, | yet someone else would reject it. I was unable to find a reference on the Cisco | web site, so perhaps we need some clarification about the accept vote, like what build | of the OS is vulnerable, since the "fail to duplicate" may be a different build of the | OS. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT] | View |
Page 362 of 20943, showing 5 records out of 104715 total, starting on record 1806, ending on 1810