CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2205  CVE-2000-0629  Candidate  The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.  Proposed (20000803)  ACCEPT(3) Cole, Dik, Levy | MODIFY(1) Frech | NOOP(3) Christey, LeBlanc, Wall  Frech> XF:sunjava-webadmin-bbs(5135) | Christey> Need to create/update | Dik> (through internal confirmation)  View
3104  CVE-2001-0283  Candidate  Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.  Proposed (20010404)  MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:sunftp-gain-access(6195)  View
1429  CVE-1999-1449  Candidate  SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.  Proposed (20010912)  MODIFY(1) Frech | NOOP(2) Cole, Foat  Frech> XF:sun-tcx-dos(7197)  View
775  CVE-1999-0795  Candidate  The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.  Proposed (19991222)  ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(1) Ozancin  Frech> XF:sun-nisplus  View
281  CVE-1999-0282  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1584, CVE-1999-1586. Reason: This candidate combined references from one issue with the description from another issue. Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name. All references and descriptions in this candidate have been removed to prevent accidental usage.  Modified (20050830)  ACCEPT(2) Baker, Dik | MODIFY(1) Frech | NOOP(1) Ozancin | RECAST(1) Prosser | REJECT(1) Christey  Frech> XF:sun-loadmodule | XF:sun-modload (CERT CA-93.18 very old!) | Prosser> Believe the reference given, 95-12, is referencing a later | loadmodule(8) setuid problem in the X11/NeWS windowing system. There is an | earlier, similar setuid vulnerability in the CA-93.18, CIAC G-02 advisories | for the SunOS 4.1.x/Solbourne and OpenWindow 3.0. In fact, there may be the | same as the HP patches are 100448-02 for the 93 loadmodule/modload | vulnerability and 100448-03 for the 95 loadmodule vulnerability which | normally indicated a patch update. Looks like the original patch either | didn"t completely fix the problem or it resurfaced in X11 NeWS. Can"t tell | much beyond that and this is my opinion only as have no way to check it. | Which one is this CVE referencing? I accept both. | Dik> There are three similar Sun bug ids associated with the patches. | 1076118 loadmodule has a security vulnerability | 1148753 loadmodule has a security vulnerability | 1222192 loadmodule has a security vulnerability | as well as: | 1137491 | Ancient stuff. | Christey> Add period to the end of the description. | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> This is distinct from CVE-1999-1584 - CVE-1999-1584 is for | CA-93.18. | CHANGE> [Christey changed vote from REVIEWING to REJECT] | Christey> This candidate combines two separate issues. It uses the CERT | alert reference from 1995, from one issue, but a description that | is associated with a separate issue.  View

Page 74 of 20943, showing 5 records out of 104715 total, starting on record 366, ending on 370

Actions