CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2374 | CVE-2000-0798 | Candidate | The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files. | Modified (20060626) | ACCEPT(3) Baker, Levy, Williams | NOOP(3) Christey, Cole, Wall | Christey> XF:irix-xfs-truncate | http://xforce.iss.net/static/5011.php | Christey> XF:sgi-xfs(2110) ? | SGI:19970102-01-PX ? | Christey> Consulting SGI on this... the relationship is pretty close. | View |
5022 | CVE-2002-0632 | Candidate | Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server. | Modified (20060626) | ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall | Christey> BID:5448 | URL:http://www.securityfocus.com/bid/5448 | XF:irix-bds-unauth-access(9825) | URL:http://www.iss.net/security_center/static/9825.php | | Change desc to "unknown vulnerability" | Frech> XF:irix-bds-unauth-access(9825) | View |
1266 | CVE-1999-1286 | Candidate | addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file. | Modified (20060623) | ACCEPT(1) Frech | NOOP(3) Christey, Cole, Foat | Christey> CHANGE DESC: "via a symlink attack on the printers temporary file." | Add 5.3 as another affected version. | | MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX | SGI:19961203-02-PX may solve this problem, but the advisory is so | vague that it is uncertain whether this was fixed or not. addnetpr is | not specifically named in the advisory, which names netprint, which is | not specified in the original Bugtraq post. In addition, the date on | the advisory is one day earlier than that of the Bugtraq post, though | that could be a difference in time zones. It seems plausible that the | problem had already been patched (the researcher did say "There *was* | [a] race condition") so maybe SGI released this advisory after the | problem was publicized. | | ADDREF BID:330 | URL:http://www.securityfocus.com/bid/330 | | Note: this is a dupe of CVE-1999-1410, but CVE-1999-1410 will | be rejected in favor of CVE-1999-1286. | View |
5694 | CVE-2002-1310 | Candidate | Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name. | Modified (20060616) | ACCEPT(3) Armstrong, Baker, Cole | NOOP(1) Cox | REVIEWING(1) Wall | Baker> http://www.macromedia.com/v1/handlers/index.cfm?ID=23500 | View |
1599 | CVE-2000-0021 | Candidate | Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin. | Modified (20060616) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Christey | Frech> XF:http-cgi-lotus-domino | Levy> BID 881 | Christey> BID:881 | View |
Page 488 of 20943, showing 5 records out of 104715 total, starting on record 2436, ending on 2440