CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5042 | CVE-2002-0652 | Candidate | xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export_fs(). | Proposed (20020726) | ACCEPT(1) Baker | NOOP(5) Christey, Cole, Cox, Foat, Wall | Christey> XF:irix-xfsmd-execute-commands(9402) | URL:http://www.iss.net/security_center/static/9402.php | BID:5075 | URL:http://www.securityfocus.com/bid/5075 | View |
7002 | CVE-2003-0173 | Candidate | xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges. | Assigned (20030328) | NOOP(1) Christey | Christey> MANDRAKE:MDKSA-2003:047 | (as suggested by Vincent Danen of Mandrake) | View |
433 | CVE-1999-0434 | Candidate | XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. | Proposed (19990728) | ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:xfree86-xfs-symlink-dos | Christey> Is this the same problem as CVE-1999-0433? CVE-1999-0433 | deals with a symlink attack on one file (/tmp/.X11-unix), | while xfs (this candidate) deals with /tmp/.font-unix | XF:xfree86-xfs-symlink-dos doesn"t exist. | Christey> ADDREF DEBIAN:19990331 symbolic link can be used to make any file world readable | Note: Debian"s advisory says that this is not a problem for Debian. | View |
432 | CVE-1999-0433 | Entry | XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. | View | |||
8521 | CVE-2004-0093 | Entry | XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI). | View |
Page 89 of 20943, showing 5 records out of 104715 total, starting on record 441, ending on 445