CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4539 | CVE-2002-0145 | Candidate | chuid 1.2 and earlier does not properly verify the ownership of files that will be changed, which allows remote attackers to change files owned by other users, such as root. | Modified (20050527) | ACCEPT(3) Balinsky, Cole, Green | MODIFY(1) Frech | NOOP(3) Foat, Wall, Ziese | Frech> XF:chuid-unauthorized-ownership-change(7976) | View |
8470 | CVE-2004-0042 | Candidate | vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames. | Modified (20050526) | ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Wall, Williams | REJECT(1) Cox | Williams> insufficient data. | CHANGE> [Cox changed vote from REVIEWING to REJECT] | Cox> Expected behaviour. By source code analysis the difference in | behaviour mentioned in the report only occurs when an administrator has | configured the server with an explicit userlist - either to allow or deny | all users in the userlist. The vsftpd manual page states that if a | userlist is used then the user will be denied access before they are asked | for a password to help prevent cleartext passwords being transmitted. | Administrators who don"t want this behaviour do not need to configure an | optional userlist. | View |
4128 | CVE-2001-1324 | Candidate | cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges. | Modified (20050526) | ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:idtools-cmvlogin-root-privileges(9987) | View |
4678 | CVE-2002-0286 | Candidate | The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user. | Modified (20050526) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | Frech> XF:sitenews-getpassword-add-users(8181) | CONFIRM:http://www.securitytracker.com/alerts/2002/Feb/100349 | 8.html | View |
3659 | CVE-2001-0853 | Candidate | Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat. | Modified (20050526) | ACCEPT(4) Armstrong, Baker, Bishop, Cole | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:getaccess-shellscripts-retrieve-files(7474) | View |
Page 523 of 20943, showing 5 records out of 104715 total, starting on record 2611, ending on 2615