CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4686  CVE-2002-0294  Candidate  Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:omnipcx-shutdown-permissions(8226) | REASON: LIKELY | Christey> Acknowledged by Alcatel via email October 4, 2002  View
4687  CVE-2002-0295  Candidate  Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.  Proposed (20020502)  MODIFY(1) Frech | NOOP(5) Christey, Cole, Cox, Foat, Wall  Frech> XF:omnipcx-insecure-groups(8227) | REASON: LIKELY | Christey> Acknowledged by Alcatel via email October 4, 2002  View
4688  CVE-2002-0296  Candidate  The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.  Modified (20050527)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:tarantella-tmp-spinning-symlink(8223)  View
4689  CVE-2002-0297  Candidate  Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:scriptease-long-http-dos(8236)  View
4690  CVE-2002-0298  Candidate  ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character.  Proposed (20020502)  MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall  Frech> XF:scriptease-get-dos(8250)  View

Page 938 of 20943, showing 5 records out of 104715 total, starting on record 4686, ending on 4690

Actions