CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3436  CVE-2001-0623  Candidate  sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.  Modified (20050309)  ACCEPT(2) Baker, Frech | NOOP(5) Bishop, Cole, Foat, Wall, Ziese | REVIEWING(1) Christey  CHANGE> [Bishop changed vote from REVIEWING to NOOP] | Christey> Need to figure out if this is one or multiple problems. | (See BIDs 2631, 2652, and 2645).  View
3437  CVE-2001-0624  Candidate  QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos.  Proposed (20010727)  ACCEPT(1) Frech | NOOP(4) Cole, Foat, Wall, Ziese | REVIEWING(1) Bishop    View
3438  CVE-2001-0625  Entry  ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log .        View
3439  CVE-2001-0626  Entry  O"Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.        View
3440  CVE-2001-0627  Entry  vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack.        View

Page 688 of 20943, showing 5 records out of 104715 total, starting on record 3436, ending on 3440

Actions