CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
88 | CVE-1999-0088 | Candidate | IRIX and AIX automountd services (autofsd) allow remote users to execute root commands. | Proposed (19990617) | ACCEPT(2) Northcutt, Shostack | MODIFY(2) Frech, Prosser | RECAST(1) Baker | REVIEWING(1) Christey | Frech> ERS (and other references, BTW) explicitly stipulate "local and | remote". | Reference: XF:irix-autofsd | Prosser> Include the SGI Alert as well since it is mentioned in the | description. | SGI Security Advisory 19981005-01-PX | Christey> DUPE CVE-1999-0210? | Christey> ADDREF CIAC:J-014 | Baker> It does look very similar to 1999-0210. Perhaps they should be a single entry | View |
89 | CVE-1999-0089 | Candidate | Buffer overflow in AIX libDtSvc library can allow local users to gain root access. | Interim (19990630) | ACCEPT(2) Northcutt, Shostack | MODIFY(2) Frech, Prosser | RECAST(1) Baker | REVIEWING(1) Christey | Frech> Reference: XF:ibm-libDtSvc | Prosser> The overflow is in the dtaction utility. Also affects | dtaction in the CDE on versions of SunOS (SUN 164). Probably should be | specific. | Christey> Same Codebase as CVE-1999-0121, so the two entries should be | merged. | View |
156 | CVE-1999-0156 | Candidate | wu-ftpd FTP daemon allows any user and password combination. | Proposed (19990714) | ACCEPT(2) Northcutt, Shostack | NOOP(1) Baker | RECAST(1) Frech | REVIEWING(2) Christey, Prosser | Prosser> but so far can find no reference to this one | Frech> Our records indicate that this does not necessarly affect just wu-ftp (ie, | also affects IIS FTP server). | Christey> The references for XF:ftp-pwless are not specific enough, | e.g. in terms of version numbers. Perhaps this candidate | should be rejected due to insufficient information. | View |
506 | CVE-1999-0509 | Candidate | Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands. | Modified (20000114-01) | ACCEPT(2) Northcutt, Wall | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Christey | Christey> What is the right level of abstraction to use here? Should | we combine all possible interpreters into a single entry, | or have a different entry for each one? I"ve often seen | Perl separated from other interpreters - is it included | by default in some Windows web server configurations? | Christey> Add tcsh, zsh, bash, rksh, ksh, ash, to support search. | Frech> XF:http-cgi-vuln(146) | View |
566 | CVE-1999-0584 | Candidate | A Windows NT file system is not NTFS. | Proposed (19990728) | ACCEPT(2) Northcutt, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey | Wall> NTFS partition provides the security. This could be re-worded | to "A Windows NT file system is FAT" since it is either NTFS or FAT | and FAT is less secure. | Frech> XF:nt-filesys(195) | Christey> MSKB:Q214579 | MSKB:Q214579 | http://support.microsoft.com/support/kb/articles/Q100/1/08.ASP | View |
Page 889 of 20943, showing 5 records out of 104715 total, starting on record 4441, ending on 4445