CVE List

Id CVE No. Status Description Phase Votes Comments Actions
5926  CVE-2002-1542  Candidate  SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.  Modified (20071029)  NOOP(4) Armstrong, Cole, Cox, Wall    View
820  CVE-1999-0840  Candidate  Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.  Modified (20071022)  ACCEPT(4) Armstrong, Baker, Dik, Stracener | MODIFY(1) Frech | NOOP(1) Cole | REVIEWING(1) Prosser  Cole> I went to 1129 and it looks like a reference for a different | vulnerability. | Frech> In the description, should dtmailptr be dtmailpr? | XF:solaris-dtmailpr-overflow | XF:solaris-dtmail-overflow | Dik> sun bug: 4166321  View
821  CVE-1999-0841  Candidate  Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.  Modified (20071022)  ACCEPT(5) Armstrong, Baker, Cole, Dik, Stracener | MODIFY(1) Frech | REVIEWING(1) Prosser  Frech> XF:cde-mailtool-bo | Dik> bug 4163471 | (Root access is only possible when mail is send to root and he | uses dtmail to read it)  View
6878  CVE-2003-0049  Candidate  Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.  Modified (20071022)  ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall  Baker> Realizing they have acknowledged the problem, and provided a fix by allowing the administrator to select whether or not this is allowed, | I am not sure this should really be a vulnerability. If you are the administrator on a system, there are other ways I can become a user | on a system. The fact that you are the administrator (root) you can do almost anything to the system you want, including accessing files | and programs that belong to other users. From a security standpoint, if the system gets "hacked" and the administrator account is compromised, | how big of an issue is it really that the administrator can now access regular user accounts with the administrator password? I am not sure this | should really be a vulnerability. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT]  View
4479  CVE-2002-0085  Candidate  cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.  Modified (20071019)  ACCEPT(3) Cole, Green, Wall | NOOP(3) Christey, Foat, Ziese  Christey> BUGTRAQ:20020429 eSecurityOnline Security Advisory 4197 - Sun Solaris cachefsd denial of service vulnerability | URL:http://online.securityfocus.com/archive/1/270134 | BID:4634 | URL:http://online.securityfocus.com/bid/4634  View

Page 469 of 20943, showing 5 records out of 104715 total, starting on record 2341, ending on 2345

Actions