Page 13 of 154 results (0.002 seconds)

CVSS: 10.0EPSS: 1%CPEs: 4EXPL: 0

11 Dec 2000 — Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service. • http://archives.neohapsis.com/archives/bugtraq/2000-10/0356.html •

CVSS: 10.0EPSS: 0%CPEs: 4EXPL: 0

11 Dec 2000 — Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges. • http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html •

CVSS: 10.0EPSS: 0%CPEs: 74EXPL: 13

14 Nov 2000 — Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. • https://www.exploit-db.com/exploits/20187 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.5EPSS: 10%CPEs: 3EXPL: 0

14 Nov 2000 — The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/. • http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html •

CVSS: 9.1EPSS: 7%CPEs: 12EXPL: 2

14 Nov 2000 — The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method. • https://www.exploit-db.com/exploits/20210 •

CVSS: 10.0EPSS: 1%CPEs: 9EXPL: 0

21 Sep 2000 — String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges. • http://www.novell.com/linux/security/advisories/suse_security_announce_58.html •

CVSS: 10.0EPSS: 34%CPEs: 32EXPL: 5

16 Jul 2000 — rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges. • https://www.exploit-db.com/exploits/20075 •

CVSS: 10.0EPSS: 1%CPEs: 4EXPL: 1

10 Jul 2000 — Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output. • http://archives.neohapsis.com/archives/vendor/2000-q3/0002.html •

CVSS: 10.0EPSS: 6%CPEs: 4EXPL: 2

24 May 2000 — Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request. • https://www.exploit-db.com/exploits/19948 •

CVSS: 7.8EPSS: 0%CPEs: 24EXPL: 3

22 May 2000 — Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter. • https://www.exploit-db.com/exploits/19952 •