CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
30 | CVE-1999-0030 | Candidate | root privileges via buffer overflow in xlock command on SGI IRIX systems. | Proposed (19990623) | ACCEPT(3) Levy, Ozancin, Prosser | NOOP(1) Baker | RECAST(1) Frech | REJECT(1) Christey | Frech> XF:xlock-bo (also add) | As per xlock-bo, also appears on AIX, BSDI, DG/UX, FreeBSD, Solaris, and | several Linii. | Also, don"t you mean to cite SGI:19970502-02-PX? The one you list is | login/scheme. | Levy> Notice that this xlock overflow is the same as in | CA-97.13. CA-97.21 simply is a reminder. | Christey> As pointed out by Elias, CA-97.21 states: "For more | information about vulnerabilities in xlock... see CA-97.13" | CA-97.13 = CVE-1999-0038. | This may also be a duplicate with CVE-1999-0306. | | See exploits at: | | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418394&w=2 | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418404&w=2 | | Sun also has this problem, at | http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/150&type=0&nav=sec.sba | View |
318 | CVE-1999-0319 | Candidate | Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting. | Proposed (19990623) | ACCEPT(3) Frech, Hill, Northcutt | NOOP(2) Baker, Prosser | REVIEWING(1) Christey | Christey> BUGTRAQ:19961126 Security Problems in XMCD 2.1 | A followup to this post says that xmcd is not suid here. | View |
92 | CVE-1999-0092 | Candidate | Various vulnerabilities in the AIX portmir command allows local users to obtain root access. | Proposed (19990623) | ACCEPT(2) Baker, Bollinger | MODIFY(1) Frech | NOOP(1) Ozancin | Frech> XF:ibm-portmir | View |
353 | CVE-1999-0354 | Candidate | Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn"t warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message. | Proposed (19990623) | ACCEPT(3) Baker, Ozancin, Wall | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:word97-template-macro | Christey> CHANGEREF NTBUGTRAQ:19990127 IE 4/5/Outlook + Word 97 security hole | URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91747570922757&w=2 | BID:196 | http://www.securityfocus.com/bid/196 | Christey> MSKB:Q214652 | http://support.microsoft.com/support/kb/articles/q214/6/52.asp | View |
127 | CVE-1999-0127 | Candidate | swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access. | Proposed (19990623) | ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | NOOP(1) Christey | Frech> (keep current XF: reference, and add) | XF:hpux-sqwmodify | Christey> Perhaps this should be split, per SF-LOC. | Christey> CIAC:H-81 | http://ciac.llnl.gov/ciac/bulletins/h-81.shtml | HP:HPSBUX9707-064 references CERT:CA-96.27 | http://ciac.llnl.gov/ciac/bulletins/h-81.shtml | | The original AUSCERT advisory says that the programs "create | files in an insecure manner" and "Exploit details involving | this vulnerability have been made publicly available." which | leads one to assume that the following original Bugtraq post | provides the details for a standard symlink problem: | | BUGTRAQ:19961005 swinst,bug | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419941&w=2 | View |
Page 426 of 20943, showing 5 records out of 104715 total, starting on record 2126, ending on 2130