Page 70 of 363 results (0.008 seconds)

CVSS: 4.6EPSS: 0%CPEs: 2EXPL: 0

The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf. • http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html http://marc.info/?l=bugtraq&m=87602661419259&w=2 http://www.iss.net/security_center/static/7244.php http://www.redhat.com/support/errata/rh42-errata-general.html#db •

CVSS: 7.2EPSS: 0%CPEs: 11EXPL: 0

Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. • http://www.securityfocus.com/bid/611 http://www.securityfocus.com/bid/759 •

CVSS: 7.2EPSS: 0%CPEs: 11EXPL: 1

Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable. • https://www.exploit-db.com/exploits/19474 http://www.securityfocus.com/bid/611 •

CVSS: 7.2EPSS: 0%CPEs: 30EXPL: 1

The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing. • https://www.exploit-db.com/exploits/19255 http://marc.info/?l=bugtraq&m=94935300520617&w=2 •

CVSS: 4.6EPSS: 0%CPEs: 14EXPL: 1

XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. • https://www.exploit-db.com/exploits/19257 https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0433 •