CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2582 | CVE-2000-1013 | Candidate | The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. | Proposed (20001129) | ACCEPT(2) Cole, Mell | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:freebsd-display-read-files(5645) | View |
2485 | CVE-2000-0916 | Candidate | FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. | Proposed (20001129) | ACCEPT(2) Cole, Mell | MODIFY(1) Frech | REVIEWING(1) Christey | Frech> XF:tcp-seq-predict(139) | Christey> Abstraction issue: CVE-1999-0077 is for TCP sequence | prediction as a general problem; but here we have a specific | implementation flaw. | View |
2532 | CVE-2000-0963 | Candidate | Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS. | Modified (20080819) | ACCEPT(2) Cole, Mell | MODIFY(1) Frech | REVIEWING(1) Christey | Christey> Various vendor writeups indicate that there are multiple | overflows, so maybe this needs to be SPLIT. | | ADDREF FREEBSD:FreeBSD-SA-00:68 | ADDREF DEBIAN:20001121 ncurses: local privilege escalation | http://www.debian.org/security/2000/20001121 | ADDREF REDHAT:RHSA-2000:115 | http://www.redhat.com/support/errata/RHSA-2000-115.html | BUGTRAQ:20001201 Immunix OS Security update for ncurses | http://marc.theaimsgroup.com/?l=bugtraq&m=97570745306444&w=2 | Frech> XF:libmytinfo-bo(4422) | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> This is all a library issue in which TERM/TERMINFO_DIRS are | one possible attack vector, but another is through entries | in the .terminfo file. Add .terminfo and termcap to the | description, as well as libncurses. | | ADDREF MANDRAKE:MDKSA-2001:052 | URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-052.php3 | | Now need to examine whether this is a dupe of CVE-2002-0062, | and/or BID:2116. There"s certainly enough confusion to go | around. | CHANGE> [Christey changed vote from REVIEWING to NOOP] | Christey> This is not a dupe of CVE-2002-0062. As explained in | DEBIAN:DSA-113, the original patches for CVE-2000-0963 | didn"t catch every problem. | | ADDREF SUSE:SuSE-SA:2000:043 | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97267560724404&w=2 | CHANGE> [Christey changed vote from NOOP to REVIEWING] | View |
830 | CVE-1999-0850 | Candidate | The default permissions for Endymion MailMan allow local users to read email or modify files. | Proposed (19991208) | ACCEPT(2) Cole, Stracener | MODIFY(1) Frech | NOOP(2) Armstrong, Baker | REVIEWING(1) Prosser | Frech> XF:endymion-mailman-perms | View |
1534 | CVE-1999-1554 | Candidate | /usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users. | Modified (20020218-01) | ACCEPT(2) Cole, Stracener | MODIFY(1) Frech | NOOP(2) Foat, Wall | Frech> XF:sgi-irix-reset(3164) | CHANGE> [Foat changed vote from ACCEPT to NOOP] | View |
Page 847 of 20943, showing 5 records out of 104715 total, starting on record 4231, ending on 4235