<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>CVE : Nchovy &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</title>
  <link type="text/html" href="http://nchovy.kr/security/cve" rel="alternate"/>
  <author>
    <name>NCHOVY &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</name>
    <email>xeraph@nchovy.kr</email>
  </author>
  <entry>
    <title>CVE-2010-0411</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0411</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0411" rel="alternate"/>
    <content>Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.</content>
    <published>2010-02-08T00:00:00+09:00</published>
    <updated>2010-02-08T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0294</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0294</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0294" rel="alternate"/>
    <content>chronyd in Chrony before 1.23.1, and possibly 1.24-pre1, generates a syslog message for each unauthorized cmdmon packet, which allows remote attackers to cause a denial of service (disk consumption) via a large number of invalid packets.</content>
    <published>2010-02-08T00:00:00+09:00</published>
    <updated>2010-02-08T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0293</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0293</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0293" rel="alternate"/>
    <content>The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, which allows remote attackers to cause a denial of service (memory consumption) via spoofed (1) NTP or (2) cmdmon packets.</content>
    <published>2010-02-08T00:00:00+09:00</published>
    <updated>2010-02-08T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0292</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0292</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0292" rel="alternate"/>
    <content>The read_from_cmd_socket function in cmdmon.c in chronyd in Chrony before 1.23.1, and 1.24-pre1, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a spoofed cmdmon packet that triggers a continuous exchange of NOHOSTACCESS messages between two daemons, a related issue to CVE-2009-3563.</content>
    <published>2010-02-08T00:00:00+09:00</published>
    <updated>2010-02-08T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2003-1588</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2003-1588</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2003-1588" rel="alternate"/>
    <content>Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file.</content>
    <published>2010-02-08T00:00:00+09:00</published>
    <updated>2010-02-08T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0559</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0559</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0559" rel="alternate"/>
    <content>The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an unspecified impact via vectors related to using kclient to join a Windows Active Directory domain.</content>
    <published>2010-02-08T00:00:00+09:00</published>
    <updated>2010-02-08T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0558</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0558</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0558" rel="alternate"/>
    <content>The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an unspecified impact via vectors related to using smbadm to join a Windows Active Directory domain.</content>
    <published>2010-02-08T00:00:00+09:00</published>
    <updated>2010-02-08T00:00:00+09:00</updated>
  </entry>
  <entry>
    <title>CVE-2010-0557</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2010-0557</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2010-0557" rel="alternate"/>
    <content>IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.</content>
    <published>2010-02-08T00:00:00+09:00</published>
    <updated>2010-02-08T00:00:00+09:00</updated>
  </entry>
</feed>
