CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30  CVE-1999-0030  Candidate  root privileges via buffer overflow in xlock command on SGI IRIX systems.  Proposed (19990623)  ACCEPT(3) Levy, Ozancin, Prosser | NOOP(1) Baker | RECAST(1) Frech | REJECT(1) Christey  Frech> XF:xlock-bo (also add) | As per xlock-bo, also appears on AIX, BSDI, DG/UX, FreeBSD, Solaris, and | several Linii. | Also, don"t you mean to cite SGI:19970502-02-PX? The one you list is | login/scheme. | Levy> Notice that this xlock overflow is the same as in | CA-97.13. CA-97.21 simply is a reminder. | Christey> As pointed out by Elias, CA-97.21 states: "For more | information about vulnerabilities in xlock... see CA-97.13" | CA-97.13 = CVE-1999-0038. | This may also be a duplicate with CVE-1999-0306. | | See exploits at: | | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418394&w=2 | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418404&w=2 | | Sun also has this problem, at | http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/150&type=0&nav=sec.sba  View
318  CVE-1999-0319  Candidate  Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.  Proposed (19990623)  ACCEPT(3) Frech, Hill, Northcutt | NOOP(2) Baker, Prosser | REVIEWING(1) Christey  Christey> BUGTRAQ:19961126 Security Problems in XMCD 2.1 | A followup to this post says that xmcd is not suid here.  View
92  CVE-1999-0092  Candidate  Various vulnerabilities in the AIX portmir command allows local users to obtain root access.  Proposed (19990623)  ACCEPT(2) Baker, Bollinger | MODIFY(1) Frech | NOOP(1) Ozancin  Frech> XF:ibm-portmir  View
353  CVE-1999-0354  Candidate  Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn"t warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.  Proposed (19990623)  ACCEPT(3) Baker, Ozancin, Wall | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:word97-template-macro | Christey> CHANGEREF NTBUGTRAQ:19990127 IE 4/5/Outlook + Word 97 security hole | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91747570922757&w=2 | BID:196 | http://www.securityfocus.com/bid/196 | Christey> MSKB:Q214652 | http://support.microsoft.com/support/kb/articles/q214/6/52.asp  View
127  CVE-1999-0127  Candidate  swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.  Proposed (19990623)  ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | NOOP(1) Christey  Frech> (keep current XF: reference, and add) | XF:hpux-sqwmodify | Christey> Perhaps this should be split, per SF-LOC. | Christey> CIAC:H-81 | http://ciac.llnl.gov/ciac/bulletins/h-81.shtml | HP:HPSBUX9707-064 references CERT:CA-96.27 | http://ciac.llnl.gov/ciac/bulletins/h-81.shtml | | The original AUSCERT advisory says that the programs "create | files in an insecure manner" and "Exploit details involving | this vulnerability have been made publicly available." which | leads one to assume that the following original Bugtraq post | provides the details for a standard symlink problem: | | BUGTRAQ:19961005 swinst,bug | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419941&w=2  View

Page 426 of 20943, showing 5 records out of 104715 total, starting on record 2126, ending on 2130

Actions