CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2266  CVE-2000-0690  Candidate  Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.  Proposed (20000921)  ACCEPT(1) Baker | MODIFY(2) Frech, Levy | NOOP(3) Christey, Cole, Wall  Levy> Reference: BID 1645 | Christey> BID:1645 | URL:http://www.securityfocus.com/bid/1645 | Frech> XF:auction-weaver-execute-commands(6175)  View
2267  CVE-2000-0691  Candidate  The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.  Proposed (20000921)  ACCEPT(1) Levy | MODIFY(2) Cox, Frech | NOOP(3) Christey, Cole, Wall  Frech> XF:mgetty-faxrunq-symlink | Christey> ADDREF XF:mgetty-faxrunq-symlink | ADDREF URL:http://xforce.iss.net/static/5159.php | ADDREF REDHAT:RHSA-2000:059-02 | ADDREF BUGTRAQ:20000830 Conectiva Linux Security Announcement - mgetty | ADDREF MANDRAKE:MDKSA-2000:042 | Christey> ADDREF REDHAT:RHSA-2000:059-02 | Christey> ADDREF FREEBSD:FreeBSD-SA-00:71 | ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:71.mgetty.asc | Frech> XF:mgetty-faxrunq-symlink(5159) | Cox> ADDREF REDHAT:RHSA-2000:059  View
2268  CVE-2000-0692  Candidate  ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.  Modified (20001010-1)  ACCEPT(2) Cole, Levy | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey  Frech> XF:realsecure-rskill-dos | Christey> CHANGEREF XF:realsecure-rskill-dos to XF:realsecure-frag-syn-dos? | http://xforce.iss.net/static/5133.php | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> In an email to issforum@iss.net on September 7, 2000, ISS says | that Network Sensor 3.2.2 is affected by SYN flooding, but | RealSecure 5.0 is not affected by Syn flooding. In addition, | they could not find conclusive evidence that RS 3.2.2 or 5.0 | was affected by IP fragmentation. This seems to indicate | that there are 2 *possible* problems: syn flooding (acknowledged | by ISS) and fragmentation (unconfirmed). Perhaps this | candidate needs to be split, or its description should be | rewritten to separate the 2 reported problems. | Frech> XF:realsecure-rskill-dos(5133)  View
2269  CVE-2000-0693  Entry  pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program.        View
2270  CVE-2000-0694  Entry  pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack.        View

Page 454 of 20943, showing 5 records out of 104715 total, starting on record 2266, ending on 2270

Actions