CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4431  CVE-2002-0037  Candidate  Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document"s object via a Notes API call (NSFDbReadObject) that directly accesses the object.  Modified (20050528)  ACCEPT(3) Cole, Green, Wall | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cox, Foat  Christey> Need to find some references for these... probably in | the CERT/CC vulnerability notes. | Frech> XF:lotus-domino-nsfdbreadobject(10095) | http://www.kb.cert.org/vuls/id/657899 | CONFIRM: | http://www-1.ibm.com/support/docview.wss?rs=1&org=sims&doc=CCA46CF459B | A6E4A85256AE3007C92C1 | Christey> Is this the same issue here? | BUGTRAQ:20011217 Lotus Notes: File attachments may be extracted regardless of document security | URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0147.html  View
4432  CVE-2002-0038  Entry  Vulnerability in the cache-limiting function of the unified name service daemon (nsd) in IRIX 6.5.4 through 6.5.11 allows remote attackers to cause a denial of service by forcing the cache to fill the disk.        View
4433  CVE-2002-0039  Candidate  rpcbind in SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via malformed RPC packets with invalid lengths.  Proposed (20020502)  ACCEPT(2) Cole, Green | MODIFY(1) Frech | NOOP(4) Armstrong, Cox, Foat, Wall | RECAST(3) Baker, Christey, Levy  Christey> CVE-2002-0039 (SGI rpcbind) is the same problem as | CVE-2001-1124 (HP rpcbind). These 2 candidates need to be | merged. | Christey> Consider adding BID:4386 | Christey> XF:irix-invalid-rpc-dos(8668) | URL:http://www.iss.net/security_center/static/8668.php | BID:4386 | URL:http://www.securityfocus.com/bid/4386 | Levy> BID 4386 will be merged into BID 3400. | Frech> XF:irix-invalid-rpc-dos(8668)  View
4434  CVE-2002-0040  Entry  Vulnerability in SGI IRIX 6.5.11 through 6.5.15f allows local users to cause privileged applications to dump core via the HOSTALIASES environment variable, which might allow the users to gain privileges.        View
4435  CVE-2002-0041  Candidate  Unknown vulnerability in Mail for SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, when running with the -R option, allows local and remote attackers to cause a core dump.  Modified (20050707)  ACCEPT(3) Armstrong, Cole, Green | MODIFY(1) Frech | NOOP(3) Cox, Foat, Wall  Frech> XF:irix-mail-core-dump(8835)  View

Page 887 of 20943, showing 5 records out of 104715 total, starting on record 4431, ending on 4435

Actions