CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4 | CVE-1999-0004 | Candidate | MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook. | Modified (19990621-01) | ACCEPT(8) Baker, Cole, Collins, Dik, Landfield, Magdych, Northcutt, Wall | MODIFY(1) Frech | NOOP(1) Christey | REVIEWING(1) Shostack | Frech> Extremely minor, but I believe e-mail is the correct term. (If you reject | this suggestion, I will not be devastated.) :-) | Christey> This issue seems to have been rediscovered in | BUGTRAQ:20000515 Eudora Pro & Outlook Overflow - too long filenames again | http://marc.theaimsgroup.com/?l=bugtraq&m=95842482413076&w=2 | | Also see | BUGTRAQ:19990320 Eudora Attachment Buffer Overflow | http://marc.theaimsgroup.com/?l=bugtraq&m=92195396912110&w=2 | Christey> | CVE-2000-0415 may be a later rediscovery of this problem | for Outlook. | Dik> Sun bug 4163471, | Christey> ADDREF BID:125 | Christey> BUGTRAQ:19980730 Long Filenames & Lotus Products | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526201&w=2 | View |
78 | CVE-1999-0078 | Candidate | pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. | Modified (19990621-01) | ACCEPT(5) Collins, Frech, Landfield, Northcutt, Shostack | NOOP(1) Baker | RECAST(1) Christey | Christey> This candidate should be SPLIT, since there are two separate | software flaws. One is a symlink race and the other is a | shell metacharacter problem. | Christey> The permissions part of this vulnerability appears to | overlap with CVE-1999-0353 | Christey> SGI:20020802-01-I | View |
3254 | CVE-2001-0436 | Candidate | dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program. | Interim (20010911) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | Frech> XF:dcforum-az-expr(6392) | View |
3255 | CVE-2001-0437 | Candidate | upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file. | Interim (20010911) | ACCEPT(3) Baker, Cole, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:dcforum-az-file-upload(6393) | View |
3069 | CVE-2001-0248 | Candidate | Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings. | Interim (20010911) | ACCEPT(5) Baker, Cole, Prosser, Renaud, Ziese | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:ftp-glob-expansion(6332) | Prosser> HPSBUX0107-162. Probably should change description to add the | HP-UX 10.01, 10.10, 10.20, 10.24 (VVOS), 11.04 (VVOS) and 11.11 | versions of the operating system as well. Patches for all systems | referenced in the advisory. | View |
Page 577 of 20943, showing 5 records out of 104715 total, starting on record 2881, ending on 2885