CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88  CVE-1999-0088  Candidate  IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.  Proposed (19990617)  ACCEPT(2) Northcutt, Shostack | MODIFY(2) Frech, Prosser | RECAST(1) Baker | REVIEWING(1) Christey  Frech> ERS (and other references, BTW) explicitly stipulate "local and | remote". | Reference: XF:irix-autofsd | Prosser> Include the SGI Alert as well since it is mentioned in the | description. | SGI Security Advisory 19981005-01-PX | Christey> DUPE CVE-1999-0210? | Christey> ADDREF CIAC:J-014 | Baker> It does look very similar to 1999-0210. Perhaps they should be a single entry  View
89  CVE-1999-0089  Candidate  Buffer overflow in AIX libDtSvc library can allow local users to gain root access.  Interim (19990630)  ACCEPT(2) Northcutt, Shostack | MODIFY(2) Frech, Prosser | RECAST(1) Baker | REVIEWING(1) Christey  Frech> Reference: XF:ibm-libDtSvc | Prosser> The overflow is in the dtaction utility. Also affects | dtaction in the CDE on versions of SunOS (SUN 164). Probably should be | specific. | Christey> Same Codebase as CVE-1999-0121, so the two entries should be | merged.  View
156  CVE-1999-0156  Candidate  wu-ftpd FTP daemon allows any user and password combination.  Proposed (19990714)  ACCEPT(2) Northcutt, Shostack | NOOP(1) Baker | RECAST(1) Frech | REVIEWING(2) Christey, Prosser  Prosser> but so far can find no reference to this one | Frech> Our records indicate that this does not necessarly affect just wu-ftp (ie, | also affects IIS FTP server). | Christey> The references for XF:ftp-pwless are not specific enough, | e.g. in terms of version numbers. Perhaps this candidate | should be rejected due to insufficient information.  View
506  CVE-1999-0509  Candidate  Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.  Modified (20000114-01)  ACCEPT(2) Northcutt, Wall | MODIFY(1) Frech | NOOP(1) Baker | REVIEWING(1) Christey  Christey> What is the right level of abstraction to use here? Should | we combine all possible interpreters into a single entry, | or have a different entry for each one? I"ve often seen | Perl separated from other interpreters - is it included | by default in some Windows web server configurations? | Christey> Add tcsh, zsh, bash, rksh, ksh, ash, to support search. | Frech> XF:http-cgi-vuln(146)  View
566  CVE-1999-0584  Candidate  A Windows NT file system is not NTFS.  Proposed (19990728)  ACCEPT(2) Northcutt, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey  Wall> NTFS partition provides the security. This could be re-worded | to "A Windows NT file system is FAT" since it is either NTFS or FAT | and FAT is less secure. | Frech> XF:nt-filesys(195) | Christey> MSKB:Q214579 | MSKB:Q214579 | http://support.microsoft.com/support/kb/articles/Q100/1/08.ASP  View

Page 889 of 20943, showing 5 records out of 104715 total, starting on record 4441, ending on 4445

Actions