CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7406  CVE-2003-0579  Candidate  uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.  Assigned (20030716)  None (candidate not yet proposed)    View
3679  CVE-2001-0873  Entry  uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option.        View
32383  CVE-2008-2266  Candidate  uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.  Assigned (20080516)  None (candidate not yet proposed)    View
10691  CVE-2004-2265  Candidate  UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact.  Assigned (20050719)  None (candidate not yet proposed)    View
4571  CVE-2002-0178  Entry  uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands.        View

Page 577 of 20943, showing 5 records out of 104715 total, starting on record 2881, ending on 2885

Actions