Page 28 of 328 results (0.008 seconds)

CVSS: 10.0EPSS: 1%CPEs: 31EXPL: 1

08 Jan 2000 — The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP. • https://www.exploit-db.com/exploits/19722 •

CVSS: 7.8EPSS: 1%CPEs: 12EXPL: 0

04 Jan 2000 — Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables. • http://www.securityfocus.com/bid/583 •

CVSS: 7.8EPSS: 0%CPEs: 8EXPL: 2

04 Jan 2000 — Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack. • https://www.exploit-db.com/exploits/19709 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

31 Dec 1999 — Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable. • http://marc.info/?l=bugtraq&m=90221103125826&w=2 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

31 Dec 1999 — linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack. • http://marc.info/?l=bugtraq&m=90383955231511&w=2 •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

31 Dec 1999 — The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf. • http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

31 Dec 1999 — netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface. • http://www.iss.net/security_center/static/7245.php •

CVSS: 9.8EPSS: 12%CPEs: 7EXPL: 1

20 Dec 1999 — wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress. • https://www.exploit-db.com/exploits/20563 •

CVSS: 5.5EPSS: 0%CPEs: 8EXPL: 1

08 Dec 1999 — The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option. • https://www.exploit-db.com/exploits/19675 •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 2

23 Nov 1999 — Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets. • https://www.exploit-db.com/exploits/20026 •