Page 22 of 138 results (0.004 seconds)

CVSS: 10.0EPSS: 0%CPEs: 10EXPL: 0

Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters. • http://www.securityfocus.com/archive/1/137890 http://www.securityfocus.com/bid/1764 https://exchange.xforce.ibmcloud.com/vulnerabilities/5344 •

CVSS: 10.0EPSS: 0%CPEs: 74EXPL: 13

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. • https://www.exploit-db.com/exploits/20187 https://www.exploit-db.com/exploits/209 https://www.exploit-db.com/exploits/215 https://www.exploit-db.com/exploits/249 https://www.exploit-db.com/exploits/20185 https://www.exploit-db.com/exploits/210 https://www.exploit-db.com/exploits/20188 https://www.exploit-db.com/exploits/20186 https://www.exploit-db.com/exploits/197 https://www.exploit-db.com/exploits/20189 https://www.exploit-db.com/exploits/20190 ftp: • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.6EPSS: 0%CPEs: 7EXPL: 0

The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges. • http://archives.neohapsis.com/archives/bugtraq/2000-07/0474.html http://archives.neohapsis.com/archives/bugtraq/2000-07/0479.html http://www.redhat.com/support/errata/RHSA-2000-030.html http://www.securityfocus.com/archive/1/73220 http://www.securityfocus.com/bid/1539 http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000802105050.A11733%40rak.isternet.sk •

CVSS: 2.1EPSS: 0%CPEs: 3EXPL: 0

DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file. • http://seclists.org/bugtraq/2000/Aug/0082.html http://seclists.org/bugtraq/2000/Aug/0096.html http://seclists.org/bugtraq/2000/Jun/0298.html http://www.securityfocus.com/bid/1552 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVSS: 3.6EPSS: 0%CPEs: 6EXPL: 2

Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service. • http://archives.neohapsis.com/archives/bugtraq/2000-07/0273.html http://www.securityfocus.com/bid/1512 •