CVE List

Id CVE No. Status Description Phase Votes Comments Actions
296  CVE-1999-0297  Entry  Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.        View
297  CVE-1999-0298  Candidate  ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.  Modified (20000524-01)  ACCEPT(4) Cole, Dik, Levy, Northcutt | MODIFY(1) Frech | NOOP(3) Baker, Christey, Shostack  Christey> ADDREF BID:1441 | URL:http://www.securityfocus.com/bid/1441 | Dik> If you run with "-ypset", then you"re always insecure. | With ypsetme, only root on the local host | can run ypset in Solaris 2.x+. | Probably true for SunOS 4, hence my vote. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> ADDREF XF:ypbind-ypset-root | CHANGE> [Dik changed vote from REVIEWING to ACCEPT] | Dik> This vulnerability does exist in SunOS 4.x in non default configurations. | In Solaris 2.x, the vulnerability only applies to files named "cache_binding" | and not all files ending in .2 | Both releases are not vulnerable in the default configuration (both | disabllow ypset by default which prevents this problem from occurring)  View
298  CVE-1999-0299  Entry  Buffer overflow in FreeBSD lpd through long DNS hostnames.        View
299  CVE-1999-0300  Entry  nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.        View
300  CVE-1999-0301  Entry  Buffer overflow in SunOS/Solaris ps command.        View

Page 60 of 20943, showing 5 records out of 104715 total, starting on record 296, ending on 300

Actions