CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7406 | CVE-2003-0579 | Candidate | uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user. | Assigned (20030716) | None (candidate not yet proposed) | View | |
3679 | CVE-2001-0873 | Entry | uuxqt in Taylor UUCP package does not properly remove dangerous long options, which allows local users to gain privileges by calling uux and specifying an alternate configuration file with the --config option. | View | |||
32383 | CVE-2008-2266 | Candidate | uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression. | Assigned (20080516) | None (candidate not yet proposed) | View | |
10691 | CVE-2004-2265 | Candidate | UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact. | Assigned (20050719) | None (candidate not yet proposed) | View | |
4571 | CVE-2002-0178 | Entry | uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands. | View |
Page 577 of 20943, showing 5 records out of 104715 total, starting on record 2881, ending on 2885