CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2374  CVE-2000-0798  Candidate  The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files.  Modified (20060626)  ACCEPT(3) Baker, Levy, Williams | NOOP(3) Christey, Cole, Wall  Christey> XF:irix-xfs-truncate | http://xforce.iss.net/static/5011.php | Christey> XF:sgi-xfs(2110) ? | SGI:19970102-01-PX ? | Christey> Consulting SGI on this... the relationship is pretty close.  View
5022  CVE-2002-0632  Candidate  Vulnerability in SGI BDS (Bulk Data Service) BDSPro 2.4 and earlier allows clients to read arbitrary files on a BDS server.  Modified (20060626)  ACCEPT(3) Armstrong, Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Cox, Foat, Wall  Christey> BID:5448 | URL:http://www.securityfocus.com/bid/5448 | XF:irix-bds-unauth-access(9825) | URL:http://www.iss.net/security_center/static/9825.php | | Change desc to "unknown vulnerability" | Frech> XF:irix-bds-unauth-access(9825)  View
1266  CVE-1999-1286  Candidate  addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.  Modified (20060623)  ACCEPT(1) Frech | NOOP(3) Christey, Cole, Foat  Christey> CHANGE DESC: "via a symlink attack on the printers temporary file." | Add 5.3 as another affected version. | | MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX | SGI:19961203-02-PX may solve this problem, but the advisory is so | vague that it is uncertain whether this was fixed or not. addnetpr is | not specifically named in the advisory, which names netprint, which is | not specified in the original Bugtraq post. In addition, the date on | the advisory is one day earlier than that of the Bugtraq post, though | that could be a difference in time zones. It seems plausible that the | problem had already been patched (the researcher did say "There *was* | [a] race condition") so maybe SGI released this advisory after the | problem was publicized. | | ADDREF BID:330 | URL:http://www.securityfocus.com/bid/330 | | Note: this is a dupe of CVE-1999-1410, but CVE-1999-1410 will | be rejected in favor of CVE-1999-1286.  View
5694  CVE-2002-1310  Candidate  Heap-based buffer overflow in the error-handling mechanism for the IIS ISAPI handler in Macromedia JRun 4.0 and earlier allows remote attackers to execute arbitrary via an HTTP GET request with a long .jsp file name.  Modified (20060616)  ACCEPT(3) Armstrong, Baker, Cole | NOOP(1) Cox | REVIEWING(1) Wall  Baker> http://www.macromedia.com/v1/handlers/index.cfm?ID=23500  View
1599  CVE-2000-0021  Candidate  Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.  Modified (20060616)  ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Frech, Levy | NOOP(1) Christey  Frech> XF:http-cgi-lotus-domino | Levy> BID 881 | Christey> BID:881  View

Page 488 of 20943, showing 5 records out of 104715 total, starting on record 2436, ending on 2440

Actions