CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
1583 | CVE-2000-0005 | Candidate | HP-UX aserver program allows local users to gain privileges via a symlink attack. | Modified (20090302) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(1) Frech | RECAST(1) Christey | REVIEWING(1) Levy | Christey> BUGTRAQ:20000102 "HPUX Aserver revisited." indicates that two | different versions of aserver have symlink problems, but with | different files. So CD:SF-LOC says we should split this. | Frech> XF:hp-aserver | Christey> BID:1928 and BID:1930? Which one is being described in | this candidate? | Christey> BID:1930 | View |
4671 | CVE-2002-0279 | Candidate | The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges. | Modified (20090302) | ACCEPT(2) Armstrong, Cole | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | Frech> XF:hp-setrlimit-kernel-panic(8195) | View |
5188 | CVE-2002-0798 | Candidate | Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service. | Modified (20090302) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(3) Cox, Foat, Wall | View | |
3928 | CVE-2001-1124 | Candidate | rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow. | Modified (20090302) | ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(3) Armstrong, Foat, Wall | RECAST(2) Baker, Christey | Christey> typo: "a malformed RPC portmap requests" | CHANGE> [Christey changed vote from NOOP to RECAST] | Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Baker> MERGE with CVE-2002-0039 | View |
3420 | CVE-2001-0607 | Candidate | asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083. | Modified (20090302) | ACCEPT(5) Baker, Bishop, Cole, Williams, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey | Frech> XF:hp-asecure-dos(6212) | Possible duplicate of CVE-2000-0083: HP asecure creates the | Audio Security File audio.sec with insecure permissions, which allows | local users to cause a denial of service or gain additional | privileges. | Williams> Frech - this is not a dupe of CVE-2000-0083. | Christey> While this advisory is vaguely worded, the fact that HP did an | advisory for the other asecure problem (now CVE-2000-0083) | indicates at the very least that this problem occurs in | a different version than CVE-2000-0083, so CD:SF-LOC | suggests a SPLIT. However, the HP advisory says "10.X" | and "11.X" are affected, so who knows what versions they | *really* mean? | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
Page 437 of 20943, showing 5 records out of 104715 total, starting on record 2181, ending on 2185