CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
434 | CVE-1999-0435 | Candidate | MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM. | Proposed (19990623) | ACCEPT(2) Baker, Ozancin | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:hp-servicegaurd | Christey> ADDREF CIAC:J-039 | Christey> Note the typo in Andre"s suggested reference. | Normalize to XF:hp-serviceguard(2046) | View |
237 | CVE-1999-0238 | Candidate | php.cgi allows attackers to read any file on the system. | Proposed (19990623) | ACCEPT(5) Baker, Collins, Frech, Northcutt, Prosser | NOOP(1) Christey | Prosser> additional source | AUSCERT External Security Bulletin ESB-97.047 | http://www.auscert.org.au | Christey> ADDREF BUGTRAQ:19970416 Update on PHP/FI hole | URL:http://www.dataguard.no/bugtraq/1997_2/0069.html | The attacker specifies the filename as an argument to the | program. | Add "PHP/FI" to description to facilitate search. | AUSCERT URL is ftp://ftp.auscert.org.au/pub/auscert/ESB/ESB-97.047 | Christey> Consider adding BID:2250 | View |
254 | CVE-1999-0255 | Candidate | Buffer overflow in ircd allows arbitrary command execution. | Proposed (19990623) | ACCEPT(3) Baker, Hill, Northcutt | MODIFY(1) Frech | NOOP(1) Prosser | REJECT(1) Christey | Frech> XF:irc-bo | Christey> This is too general and doesn"t have any references. The | XF reference doesn"t appear toe xist any more. | | Perhaps this reference would help: | BUGTRAQ:19970701 ircd buffer overflow | Baker> It appears that the XForce entry has been corrected, and there is a patch posted in the original bugtraq post. | View |
88 | CVE-1999-0088 | Candidate | IRIX and AIX automountd services (autofsd) allow remote users to execute root commands. | Proposed (19990617) | ACCEPT(2) Northcutt, Shostack | MODIFY(2) Frech, Prosser | RECAST(1) Baker | REVIEWING(1) Christey | Frech> ERS (and other references, BTW) explicitly stipulate "local and | remote". | Reference: XF:irix-autofsd | Prosser> Include the SGI Alert as well since it is mentioned in the | description. | SGI Security Advisory 19981005-01-PX | Christey> DUPE CVE-1999-0210? | Christey> ADDREF CIAC:J-014 | Baker> It does look very similar to 1999-0210. Perhaps they should be a single entry | View |
121 | CVE-1999-0121 | Candidate | Buffer overflow in dtaction command gives root access. | Proposed (19990617) | ACCEPT(2) Dik, Northcutt | MODIFY(3) Baker, Frech, Prosser | REVIEWING(1) Christey | Frech> Reference: XF:dtaction-bo | Reference: XF:sun-dtaction | Prosser> Buffer overflow also affects /usr/dt/bin/dtaction in libDtSvc.a | library in AIX 4.x, but reference for this Sun vulnerability should | only reflect the Sun Bulletin or the CIAC I-032 version of the Sun | Bulletin | Christey> This is the Same Codebase as CVE-1999-0089, so the two entries | should be merged. | Frech> Replace sun-dtaction(732) with dtaction-bo(879) | Baker> Merge with 1999-0089 | View |
Page 427 of 20943, showing 5 records out of 104715 total, starting on record 2131, ending on 2135