Page 109 of 1101 results (0.006 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

14 Nov 2000 — Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion. • http://archives.neohapsis.com/archives/bugtraq/2000-09/0040.html •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

01 Nov 2000 — The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows. • http://gcc.gnu.org/ml/gcc-bugs/2002-05/msg00198.html •

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 0

13 Oct 2000 — GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions. • http://archives.neohapsis.com/archives/bugtraq/2000-07/0389.html •

CVSS: 7.8EPSS: 0%CPEs: 7EXPL: 0

21 Sep 2000 — The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges. • http://archives.neohapsis.com/archives/bugtraq/2000-07/0474.html •

CVSS: 7.5EPSS: 1%CPEs: 8EXPL: 0

03 May 2000 — The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results. • http://www.securityfocus.com/bid/1166 •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

18 Apr 2000 — The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack. • http://www.securityfocus.com/bid/1126 •

CVSS: 7.1EPSS: 0%CPEs: 7EXPL: 0

18 Apr 2000 — Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess. • http://www.securityfocus.com/bid/1125 •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

18 Apr 2000 — read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords. • http://www.securityfocus.com/bid/1125 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

01 Feb 2000 — GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands. • http://www.securityfocus.com/bid/981 •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

05 Aug 1999 — The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code. • http://www.securityfocus.com/bid/563 •