CVE List

Id CVE No. Status Description Phase Votes Comments Actions
3986  CVE-2001-1182  Candidate  Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.  Modified (20090302)  ACCEPT(5) Armstrong, Baker, Cole, Green, Ziese | MODIFY(1) Frech | NOOP(2) Foat, Wall | REVIEWING(1) Christey  Frech> XF:hpux-login-unauthorized-access(6860) | Christey> CIAC:L-114 | URL:http://ciac.llnl.gov/ciac/bulletins/l-114.shtml | BID:3068 | URL:http://online.securityfocus.com/bid/3068 | | This would appear to be a dupe of CVE-2001-0797, but the HP advisory | from CVE-2001-0797 is too vague to be certain. As quoted in | the CERT advisory for CVE-2001-0797, HP says: | "HP-UX does have a benign buffer overflow... [which] has been | fixed by HP." HP:HPSBUX0107-160 (CVE-2001-1182) states that | "The login(1) command allows restricted shell users to | circumvent security checks" which could be interpreted as | meaning that HP has found a slightly less-than-benign aspect | of the overflow, but since (a) the advisory says nothing about | overflows and (b) the advisory does not include any | cross-references, it cannot be clear. There is a difference | in the release dates as well, however, since the HP advisory | was released in July 2001 and this CAN was publicized in | December 2001, which may be sufficient evidence that the | problems are different. | | This probably is not the same issue in login as CVE-2001-0978, | since different patches are referenced in that CAN. | | There is insufficient information to know whether this is the | same issue as CVE-2001-0094 (kerberos library issues that | affect kerberized login).  View
3987  CVE-2001-1183  Entry  PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet.        View
3988  CVE-2001-1184  Candidate  wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024.  Proposed (20020315)  ACCEPT(4) Cole, Frech, Green, Ziese | NOOP(2) Foat, Wall    View
3989  CVE-2001-1185  Entry  Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.        View
3990  CVE-2001-1186  Entry  Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.        View

Page 798 of 20943, showing 5 records out of 104715 total, starting on record 3986, ending on 3990

Actions