CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
950 | CVE-1999-0970 | Candidate | The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created. | Modified (20020226-01) | ACCEPT(3) Baker, Blake, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Levy | Frech> XF:omnihttpd-dos | Christey> Some sort of confirmation might be findable at: | http://www.omnicron.ab.ca/httpd/docs/release.html | Christey> See http://www.omnicron.ab.ca/index.html | The August 16, 2000 news item says "This release fixes some | security problems." It"s for version 2.07, but the discloser | didn"t say what version was available. | | Other security fixes are in the release notes at | http://www.omnicron.ab.ca/httpd/docs/release.html Notes for | Professional Version 1.01 say "Patched up two security weaknesses." | Notes for version 2.07 say "Fixes dot-appending vulnerability." | Professional Alpha 7 says "Revamped CGI launching and security," | Professional Alpha 4 says "Fixed SSI path mapping and security | problems," Alpha 5 says "Security fixup." | | In other words, you can"t tell whether they"ve fixed this bug | or not. | Christey> BID:1808 | URL:http://www.securityfocus.com/bid/1808 | View |
3585 | CVE-2001-0778 | Candidate | OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20). | Modified (20020225-01) | ACCEPT(1) Frech | NOOP(4) Armstrong, Cole, Foat, Wall | View | |
3388 | CVE-2001-0575 | Candidate | Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut. | Modified (20020225-01) | ACCEPT(3) Baker, Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese | Bishop> recommend combining as stated in analysis | Baker> http://support.caldera.com/caldera/solution?11=113723&130=0988647911&14=&2715=&15=&2716=&57=search&58=&2900=dckSSu3pru&25=6&3=SSE072B | "What is SSE072B, the buffer overflow security patch for Openserver 5? (Ref. #113723)" | Buffer overflows have been found in the following 19 | SCO OpenServer 5 utilities: | | /usr/bin/accept | /usr/bin/cancel | /usr/mmdf/bin/deliver | /usr/bin/disable | /usr/bin/enable | /usr/lib/libcurses.a | /usr/bin/lp | /usr/lib/lpadmin | /usr/lib/lpfilter | /usr/lib/lpforms | /usr/lib/lpmove | /usr/lib/lpshut | /usr/bin/lpstat | /usr/lib/lpusers | /usr/bin/recon | /usr/bin/reject | /usr/bin/rmail | /usr/lib/sendmail | /usr/bin/tput | | NOTE: the accept, reject, enable, and disable commands are | symbolically linked to the same binary. | | Running any of the above utilities with a very large argument | can result in a core dump. | View |
3389 | CVE-2001-0576 | Candidate | lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the "-u" command line parameter. | Modified (20020225-01) | ACCEPT(2) Frech, Williams | MODIFY(1) Bishop | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker | Bishop> recommend combining as stated in analysis | Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem. | Williams> re: Baker recast - why merge 19 separate vuln issues into one CAN? | View |
3390 | CVE-2001-0577 | Candidate | recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument. | Modified (20020225-01) | ACCEPT(2) Frech, Williams | NOOP(4) Cole, Foat, Wall, Ziese | RECAST(1) Baker | REVIEWING(1) Bishop | Baker> Merge with CVE-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem. | View |
Page 552 of 20943, showing 5 records out of 104715 total, starting on record 2756, ending on 2760