Vulnerabilities
Vulnerable Software
Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.
CVSS Score
10.0
EPSS Score
0.005
Published
2000-12-11
The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges.
CVSS Score
7.2
EPSS Score
0.0
Published
2000-12-11
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
CVSS Score
10.0
EPSS Score
0.009
Published
2000-11-14
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
CVSS Score
7.2
EPSS Score
0.001
Published
2000-11-14
The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.
CVSS Score
5.0
EPSS Score
0.053
Published
2000-11-14
A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.
CVSS Score
1.2
EPSS Score
0.001
Published
2000-10-20
Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.
CVSS Score
2.1
EPSS Score
0.001
Published
2000-07-18
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
CVSS Score
7.2
EPSS Score
0.001
Published
2000-07-03
Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.
CVSS Score
7.2
EPSS Score
0.001
Published
2000-06-21
Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.
CVSS Score
7.2
EPSS Score
0.001
Published
2000-06-21


Contact Us

Shodan ® - All rights reserved