CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
928 | CVE-1999-0948 | Candidate | Buffer overflow in uum program for Canna input system allows local users to gain root privileges. | Proposed (19991222) | ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Christey | Christey> CVE-1999-0948 and CVE-1999-0949 are extremely similar. | uum (0948) is exploitable through a different set of options | than canuum (0949). If it"s the same generic option parsing | routine used by both programs, then CD:SF-CODEBASE says to | merge them. But if it"s not, then CD:SF-LOC and CD:SF-EXEC | says to split them. However, this is a prime example of | how SF-EXEC might be modified - uum and canuum are clearly | part of the same package, so in the absence of clear | information, maybe we should merge them. | Frech> XF:canna-uum-bo | View |
929 | CVE-1999-0949 | Candidate | Buffer overflow in canuum program for Canna input system allows local users to gain root privileges. | Proposed (19991222) | ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Christey | Christey> CVE-1999-0948 and CVE-1999-0949 are extremely similar. | uum (0948) is exploitable through a different set of options | than canuum (0949). If it"s the same generic option parsing | routine used by both programs, then CD:SF-CODEBASE says to | merge them. But if it"s not, then CD:SF-LOC and CD:SF-EXEC | says to split them. However, this is a prime example of | how SF-EXEC might be modified - uum and canuum are clearly | part of the same package, so in the absence of clear | information, maybe we should merge them. | | Also review BID:758 and BID:757 - may need to change the BID | here. | Frech> XF:canna-uum-bo | Christey> CHANGEREF BID:757 BID:758 | Christey> The following page says that canuum is a "Japanese input tty | frontend for Canna using uum," which suggests that it is, at | the least, a different package, so perhaps this should stay SPLIT. | | http://wuarchive.wustl.edu/mirrors/NetBSD/NetBSD-current/pkgsrc/inputmethod/canuum/README.html | View |
1979 | CVE-2000-0401 | Candidate | Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string. | Proposed (20000615) | ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:pdgsoft-changepw-bo | XF:pdgsoft-redirect-bo | View |
2027 | CVE-2000-0449 | Candidate | Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields. | Proposed (20000615) | ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Cole, Wall | Frech> XF:omnis-studio-weak-encryption | View |
86 | CVE-1999-0086 | Candidate | AIX routed allows remote users to modify sensitive files. | Interim (19990630) | ACCEPT(2) Northcutt, Shostack | MODIFY(2) Frech, Prosser | NOOP(1) Baker | REJECT(1) Christey | Frech> Reference: XF:ibm-routed | Prosser> This vulnerability allows debug mode to be turned on which is | the problem. Should this be more specific in the description? This | one also affects SGI OSes, ref SGI Security Advisory 19981004-PX which | is in the SGI cluster, shouldn"t these be cross-referenced as the same | vuln affects multiple OSes. | Christey> This appears to be subsumed by CVE-1999-0215 | View |
Page 888 of 20943, showing 5 records out of 104715 total, starting on record 4436, ending on 4440