Page 5 of 50 results (0.012 seconds)

CVSS: 7.8EPSS: 0%CPEs: 7EXPL: 0

19 Nov 1998 — Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program. • http://www.caldera.com/support/security/advisories/SA-1998.35.txt •

CVSS: 10.0EPSS: 1%CPEs: 10EXPL: 2

12 Oct 1998 — Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. • https://www.exploit-db.com/exploits/19096 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 10.0EPSS: 9%CPEs: 76EXPL: 2

08 Apr 1998 — Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. • https://www.exploit-db.com/exploits/19111 •

CVSS: 7.5EPSS: 1%CPEs: 8EXPL: 0

16 Dec 1997 — A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. • http://www.securityfocus.com/bid/80175 •

CVSS: 9.1EPSS: 1%CPEs: 32EXPL: 0

10 Dec 1997 — FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0017 •

CVSS: 7.8EPSS: 0%CPEs: 8EXPL: 0

17 Jul 1997 — Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error. • http://marc.info/?l=bugtraq&m=87602661419318&w=2 •

CVSS: 10.0EPSS: 11%CPEs: 8EXPL: 1

07 Apr 1997 — Buffer overflow in University of Washington's implementation of IMAP and POP servers. • https://www.exploit-db.com/exploits/340 •

CVSS: 10.0EPSS: 0%CPEs: 4EXPL: 0

28 Jan 1997 — MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. • http://www.securityfocus.com/bid/685 •

CVSS: 10.0EPSS: 0%CPEs: 14EXPL: 0

04 Dec 1996 — Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 9.8EPSS: 0%CPEs: 5EXPL: 0

08 Oct 1996 — Bash treats any character with a value of 255 as a command separator. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0234 •