CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
865 | CVE-1999-0885 | Candidate | Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL. | Modified (20000313-01) | ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(5) Armstrong, Blake, Christey, Cole, LeBlanc | Christey> This candidate is unconfirmed by the vendor. | Blake> Same as CVE-1999-0776. | Frech> XF:alibaba-url-file-manipulation | Christey> CD:SF-LOC and CD:SF-EXEC may say to merge this candidate with | the problems described in: | BUGTRAQ:20000718 Multiple bugs in Alibaba 2.0 | URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html | | If so, then ADDREF BID:1485 as well. | Christey> Include the names of the affected CGI"s, including tst.bat, | get32.exe, alibaba.pl, etc. | View |
1624 | CVE-2000-0046 | Candidate | Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message. | Modified (20000204-01) | ACCEPT(2) Baker, Williams | MODIFY(1) Frech | Frech> ADDREF XF:icq-url-bo | View |
1625 | CVE-2000-0047 | Candidate | Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message. | Modified (20000202-01) | ACCEPT(2) Baker, Frech | NOOP(1) Williams | View | |
805 | CVE-1999-0825 | Candidate | The default permissions for UnixWare /var/mail allow local users to read and modify other users" mail. | Modified (20000121-01) | ACCEPT(4) Armstrong, Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Prosser | Frech> XF:sco-mail-permissions | Christey> ADDREF ftp://ftp.sco.com/SSE/security_bulletins/SB-99.25a | View |
808 | CVE-1999-0828 | Candidate | UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission. | Modified (20000121-01) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Cole, Frech | REVIEWING(2) Christey, Prosser | Cole> This is BID 850. | Christey> See comments on CVE-1999-0988. Perhaps these two should be | merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a | loosely alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:sco-pkg-dacread-fileread | View |
Page 567 of 20943, showing 5 records out of 104715 total, starting on record 2831, ending on 2835