CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
3926 | CVE-2001-1122 | Candidate | Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in "SPECIAL" mode. | Proposed (20020315) | ACCEPT(3) Foat, Frech, Green | NOOP(2) Baker, Cole | REJECT(2) Armstrong, Ziese | REVIEWING(1) Wall | Ziese> fact that important system | files are not appropriately secured from user, a/o admin, level access. | Green> ACCESS TO THE WINNT/SYSTEM32 DIRECTORY, ALLOWING FOR A DoS TO BE PERFORMED. | Foat> Our attempts to repair the computer with the Windows NT cd-rom failed. | The machine still would not allow logins. Tried two different NT 4.0 CD"s. Both | CD"s gave the error message that the file MSV1_0.dll read okay but is invalid on | the hard drive. It says the CD is probably defective. | Armstrong> I don"t believe that a privileged user being able to run code | on a system is a vulnerability. | Baker> I generally agree that unless you are elevating your priveleges, this should not be listed as a vulnerability. | CHANGE> [Baker changed vote from REVIEWING to NOOP] | View |
3927 | CVE-2001-1123 | Candidate | Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID. | Proposed (20020315) | ACCEPT(4) Baker, Cole, Frech, Green | NOOP(4) Armstrong, Foat, Wall, Ziese | View | |
3928 | CVE-2001-1124 | Candidate | rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow. | Modified (20090302) | ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(3) Armstrong, Foat, Wall | RECAST(2) Baker, Christey | Christey> typo: "a malformed RPC portmap requests" | CHANGE> [Christey changed vote from NOOP to RECAST] | Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Baker> MERGE with CVE-2002-0039 | View |
3929 | CVE-2001-1125 | Candidate | Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site. | Proposed (20020315) | ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Good split | View |
3930 | CVE-2001-1126 | Candidate | Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. | Proposed (20020315) | ACCEPT(7) Armstrong, Baker, Cole, Frech, Green, Prosser, Ziese | NOOP(2) Foat, Wall | Green> IN ONE VERSION, BUT NOT IN THE OTHER | Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html | | Concur with Analysis, this should be split. The DoS would | include all versions of LiveUpdate, 1.4.x through 1.6.x. The | potential for unauthorized code execution only impacts 1.4.x through | 1.5.x. | View |
Page 786 of 20943, showing 5 records out of 104715 total, starting on record 3926, ending on 3930