CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4076  CVE-2001-1272  Candidate  wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.  Proposed (20020502)  ACCEPT(4) Cole, Frech, Green, Wall | NOOP(2) Cox, Foat    View
4077  CVE-2001-1273  Candidate  The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).  Proposed (20020502)  ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall  CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:kernel-mxcsr-p4-dos(9995)  View
4078  CVE-2001-1274  Candidate  Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.  Proposed (20020502)  ACCEPT(3) Cole, Cox, Green | MODIFY(1) Frech | NOOP(2) Foat, Wall  Frech> XF:mysql-select-bo(5969)  View
4079  CVE-2001-1275  Candidate  MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall | REVIEWING(1) Christey  Christey> CALDERA:CSSA-2001-006.0 specifically says they"re not | vulnerable to this issue. So, do we remove the reference | (because they aren"t affected by this problem), or do we | keep the reference because it specifically mentions this | issue? | | Need to review the other advisories; they don"t necessarily | have the details to know whether they"re addressing this | problem or not (the overflow mentioned in these refs is | covered by CVE-2001-1274). MANDRAKE:MDKSA-2001:014 | clearly identifies this issue. | | FREEBSD:FreeBSD-SA-01:16 discussed "remote vulerabilities" | (plural), which *could* include this issue, but it is not | absolutely certain. REDHAT:RHSA-2001:003 refers to | "information protection issues," but that"s not clear enough | either. | | Thanks to John Segura of secureinfo.com for noticing this | issue. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:mysql-show-grants-password(9996)  View
4080  CVE-2001-1276  Entry  ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.        View

Page 816 of 20943, showing 5 records out of 104715 total, starting on record 4076, ending on 4080

Actions