Page 28 of 151 results (0.001 seconds)

CVSS: 10.0EPSS: 0%CPEs: 74EXPL: 13

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. • https://www.exploit-db.com/exploits/20187 https://www.exploit-db.com/exploits/209 https://www.exploit-db.com/exploits/215 https://www.exploit-db.com/exploits/249 https://www.exploit-db.com/exploits/20185 https://www.exploit-db.com/exploits/210 https://www.exploit-db.com/exploits/20188 https://www.exploit-db.com/exploits/20186 https://www.exploit-db.com/exploits/197 https://www.exploit-db.com/exploits/20189 https://www.exploit-db.com/exploits/20190 ftp: • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 1.2EPSS: 0%CPEs: 4EXPL: 0

A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed. • http://archives.neohapsis.com/archives/bugtraq/2000-08/0146.html http://www.securityfocus.com/bid/1567 •

CVSS: 2.1EPSS: 0%CPEs: 18EXPL: 0

Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system. • http://archives.neohapsis.com/archives/bugtraq/2000-07/0251.html http://archives.neohapsis.com/archives/bugtraq/2000-08/0117.html http://www.redhat.com/support/errata/RHSA-2000-053.html http://www.securityfocus.com/bid/1489 https://exchange.xforce.ibmcloud.com/vulnerabilities/4944 •

CVSS: 5.0EPSS: 13%CPEs: 7EXPL: 1

BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters. • https://www.exploit-db.com/exploits/20060 http://archives.neohapsis.com/archives/bugtraq/2000-07/0026.html http://archives.neohapsis.com/archives/bugtraq/2000-07/0098.html http://archives.neohapsis.com/archives/bugtraq/2000-07/0105.html http://archives.neohapsis.com/archives/freebsd/2000-07/0042.html http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0018.html http://www.calderasystems.com/support/security/advisories/CSSA-2000-022.0.txt http://www.redhat.com/support/errata/RHSA •

CVSS: 7.2EPSS: 0%CPEs: 18EXPL: 0

makewhatis in Linux man package allows local users to overwrite files via a symlink attack. • ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-021.0.txt http://archives.neohapsis.com/archives/bugtraq/2000-07/0390.html http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:015 http://www.redhat.com/support/errata/RHSA-2000-041.html http://www.securityfocus.com/bid/1434 https://exchange.xforce.ibmcloud.com/vulnerabilities/4900 •