CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3171 | CVE-2001-0350 | Candidate | Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability. | Modified (20050509) | ACCEPT(5) Armstrong, Balinsky, Cole, Foat, Ziese | MODIFY(1) Frech | RECAST(1) Stracener | REVIEWING(2) Christey, Wall | Wall> Perhaps merge 0349 and 0350 unless there is a bigger difference. | Stracener> Merge this with 0349. | Frech> XF:win2k-telnet-pipe-privileges(6664) | Christey> CIAC:L-092 | URL:http://www.ciac.org/ciac/bulletins/l-092.shtml | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> CERT-VN:VU#587587 | URL:http://www.kb.cert.org/vuls/id/587587 | BID:2849 | Microsoft identifies two separate vulnerabilities that are extremely | similar, but the security bulletin states that "The two | vulnerabilities differ primarily in the way they exploit the | underlying problem regarding named pipe creation." So, it may be | necessary to merge CVE-2001-0350 with CVE-2001-0349. | | If one issue is because of predictable names, and another | issue is because pipe ownership isn"t properly verified, then | these could stay SPLIT, and the descriptions should be | modified accordingly. | View |
3172 | CVE-2001-0351 | Entry | Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service. | View | |||
3173 | CVE-2001-0352 | Candidate | SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB. | Proposed (20010727) | ACCEPT(3) Cole, Stracener, Ziese | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Foat, Wall | Frech> XF:3com-ap-wep-key(6232) | Christey> BID:2899 | URL:http://www.securityfocus.com/bid/2899 | View |
3174 | CVE-2001-0353 | Entry | Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a "transfer job" routine. | View | |||
3175 | CVE-2001-0354 | Candidate | TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on. | Proposed (20010524) | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Williams | Frech> XF:checkbo-tcp-bo(6436) | View |
Page 635 of 20943, showing 5 records out of 104715 total, starting on record 3171, ending on 3175