12 results (0.006 seconds)

CVSS: 5.5EPSS: 2%CPEs: 9EXPL: 0

28 Oct 2002 — The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments. El procedimiento getdbm en ypxfrd permite a usuarios locales leer ficheros arbitrarios, y a atacantes remotos leer bases de datos fuera de /var/yp, mediante ataques de atravesamiento de directorios y de enlaces simbólicos en los argumentos de dominio y mapa. • ftp://ftp.caldera.com/pub/updates/OpenServer/CSSA-2002-SCO.40 •

CVSS: 9.1EPSS: 0%CPEs: 14EXPL: 0

06 Dec 2001 — Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000432 •

CVSS: 7.8EPSS: 0%CPEs: 13EXPL: 0

26 Mar 2001 — kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges. • http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt •

CVSS: 5.5EPSS: 0%CPEs: 15EXPL: 0

12 Mar 2001 — inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. • http://marc.info/?l=bugtraq&m=97916374410647&w=2 •

CVSS: 10.0EPSS: 2%CPEs: 3EXPL: 0

09 Mar 2001 — Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands. • http://www.calderasystems.com/support/security/advisories/CSSA-2001-003.0.txt •

CVSS: 10.0EPSS: 83%CPEs: 7EXPL: 5

19 Dec 2000 — Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. • https://www.exploit-db.com/exploits/227 •

CVSS: 7.2EPSS: 0%CPEs: 22EXPL: 3

19 Dec 2000 — Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. • https://www.exploit-db.com/exploits/217 •

CVSS: 7.5EPSS: 12%CPEs: 7EXPL: 1

04 Jul 2000 — BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters. • https://www.exploit-db.com/exploits/20060 •

CVSS: 7.2EPSS: 0%CPEs: 18EXPL: 0

03 Jul 2000 — makewhatis in Linux man package allows local users to overwrite files via a symlink attack. • ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-021.0.txt •

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 5

31 May 2000 — The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files. • https://www.exploit-db.com/exploits/19979 •