CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
231 | CVE-1999-0232 | Candidate | Buffer overflow in NCSA WebServer (version 1.5c) gives remote access. | Modified (19991220-01) | ACCEPT(2) Hill, Northcutt | MODIFY(1) Frech | NOOP(1) Prosser | REJECT(1) Baker | REVIEWING(1) Christey | Frech> Unable to provide a match due to vague/insufficient description/references. | Possible matches are: | XF:ftp-ncsa (probably not, considering you"ve mentioned the webserver.) | XF:http-ncsa-longurl (highest probability) | Christey> CVE-1999-0235 is the one associated with XF:http-ncsa-longurl | More research is necessary for this one. | Baker> Since this has no references at all, and is vague and we have a | CAN for the most likely issue, we should kill this one | View |
234 | CVE-1999-0235 | Candidate | Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access. | Modified (19991220-01) | ACCEPT(3) Hill, Northcutt, Prosser | MODIFY(1) Frech | REJECT(2) Baker, Christey | Frech> XF:http-ncsa-longurl | Christey> CVE-1999-0235 has the same ref"s as CVE-1999-0267 | Baker> Not to mention, the X-force listings of http-ncsa-longurl and http-port both | refer to the same problem. This should be rejected as 1999-0267 is the same problem. | View |
316 | CVE-1999-0317 | Candidate | Buffer overflow in Linux su command gives root access to local users. | Modified (19991216-01) | ACCEPT(3) Frech, Hill, Northcutt | NOOP(1) Prosser | RECAST(1) Baker | REVIEWING(1) Christey | Christey> DUPE CVE-1999-0845? | Also, ADDREF XF:unixware-su-username-bo | A report summary by Aleph One states that nobody was able to | confirm this problem on any Linux distribution. | Baker> If this is the same as the unixware, the n it is a dupe of 1999-0845. There is about a two and half month difference in the bugtraq reporting of these. | Sounds like the same bug however... | Christey> XF:su-bo no longer seems to exist. | How about XF:linux-subo(734) ? | http://xforce.iss.net/static/734.php | | BID:475 also seems to describe the same problem | (http://www.securityfocus.com/bid/475) in which case, | vsyslog is blamed in: | BUGTRAQ:19971220 Linux vsyslog() overflow | http://www.securityfocus.com/archive/1/8274 | View |
369 | CVE-1999-0370 | Candidate | In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files. | Modified (19991210-01) | ACCEPT(4) Baker, Dik, Northcutt, Prosser | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> Reference: XF:sun-man | Christey> ADDREF CIAC:J-028 | | Is the Linux man symlink problem the same as the one for Sun? | See BUGTRAQ:19990602 /tmp symlink problems in SuSE Linux 6.1 | Also see BID:305 | Dik> sun bug 4154565 | View |
454 | CVE-1999-0455 | Candidate | The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly. | Modified (19991210-01) | ACCEPT(3) Balinsky, Frech, Ozancin | MODIFY(1) Wall | NOOP(1) Baker | REVIEWING(1) Christey | Wall> The reference should be ASB99-01 (Expression Evaluator Security Issues) | make application plural since there are three sample applications | (openfile.cfm, displayopenedfile.cfm, and exprcalc.cfm). | Christey> The CD:SF-EXEC and CD:SF-LOC content decisions apply here. | Since there are 3 separate "executables" with the same | (or similar) problem, we need to make sure that CD:SF-EXEC | determines what to do here. There is evidence that some | of these .cfm scripts have an "include" file, and if so, | then CD:SF-LOC says that we shouldn"t make separate entries | for each of these scripts. On the other hand, the initial | L0pht discovery didn"t include all 3 of these scripts, and | as far as I can tell, Allaire had patched the first problem | before the others were discovered. So, CD:DISCOVERY-DATE | may argue that we should split these because the problems | were discovered and patched at different times. | | In any case, this candidate can not be accepted until the | Editorial Board has accepted the CD:SF-EXEC, CD:SF-LOC, | and CD:DISCOVERY-DATE content decisions. | View |
Page 572 of 20943, showing 5 records out of 104715 total, starting on record 2856, ending on 2860