CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4976 | CVE-2002-0585 | Candidate | Unknown vulnerability in ndd for HP-UX 11.11 with certain TRANSPORT patches allows attackers to cause a denial of service. | Modified (20090302) | ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Armstrong, Cox, Foat, Wall | Frech> XF:hp-ndd-dos(9020) | View |
5744 | CVE-2002-1360 | Candidate | Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite. | Modified (20090302) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(2) Cole, Cox | REVIEWING(1) Wall | Frech> XF:ssh-transport-null-string-bo(10871) | View |
1655 | CVE-2000-0077 | Candidate | The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands. | Modified (20090302) | MODIFY(2) Baker, Frech | REVIEWING(1) Christey | Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is October 1998 equivalent to HP-UX 10.x? | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0078. | Baker> Was the BID reference ever added to this one? | View |
1656 | CVE-2000-0078 | Candidate | The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command. | Modified (20090302) | ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> ADDREF XF:hp-aserver | Christey> The Bugtraq posting does not mention specific versions. | Is June 1999 equivalent to HP-UX 10.x? | Prosser> The HP Bulletin (already ref"d) just specifies 10.x and 11.x OS versions running on HP9000 700/800 series. According to Tripp (bugtraq), the audio server doesn"t run on a machine without Audio Hardware (logical). So one has to assume from the bulletin that any 9000 with audio hardware that is running a 10.x or 11.x version of OS with either the 98 or 99 version of Aserver loaded will be vulnerable to either the exploit in CVE-1999-0005(the 98 version of Aserver) or CVE-2000-0078 (the 99 version)and should take appropriate action. No patches out from HP as of 10/2/2000 so either remove the program or tighten the permissions considerably. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> BID:1929 | Make sure not dupe"s with CVE-2000-0005 and CVE-20000-0077. | View |
3198 | CVE-2001-0380 | Candidate | Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string "ILMI". | Modified (20090302) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | Frech> XF:cisco-ios-modify-snmp(6169) | Christey> Fix the date of the Bugtraq post | Christey> The Bugtraq poster didn"t provide many details, but said that | the vendor was out of business. It"s possible that this ILMI | community string has no relationship with the Cisco ILMI | problem, in which case this should remain a separate CAN. | Christey> Further research suggests that ILMI is a standard | specification for ATM, and therefore this CAN should remain split from | the Cisco ILMI problem (CVE-2001-0711). | View |
Page 439 of 20943, showing 5 records out of 104715 total, starting on record 2191, ending on 2195