CVE-2000-0566
|
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
Published:
July 03, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0585
|
ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters.
Published:
June 24, 2000; 12:00:00 AM -04:00
|
V2: 10.0 HIGH
|
CVE-2000-0617
|
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.
Published:
June 22, 2000; 12:00:00 AM -04:00
|
V2: 4.6 MEDIUM
|
CVE-2000-0618
|
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.
Published:
June 22, 2000; 12:00:00 AM -04:00
|
V2: 4.6 MEDIUM
|
CVE-2000-0602
|
Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.
Published:
June 21, 2000; 12:00:00 AM -04:00
|
V2: 4.6 MEDIUM
|
CVE-2000-0604
|
gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.
Published:
June 21, 2000; 12:00:00 AM -04:00
|
V2: 4.6 MEDIUM
|
CVE-2000-0606
|
Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.
Published:
June 21, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0607
|
Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.
Published:
June 21, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0506
|
The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."
Published:
June 09, 2000; 12:00:00 AM -04:00
|
V2: 10.0 HIGH
|
CVE-2000-0467
|
Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.
Published:
June 01, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0530
|
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.
Published:
May 31, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0454
|
Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter.
Published:
May 29, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0460
|
Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.
Published:
May 27, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0442
|
Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.
Published:
May 24, 2000; 12:00:00 AM -04:00
|
V2: 7.5 HIGH
|
CVE-2000-0491
|
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.
Published:
May 24, 2000; 12:00:00 AM -04:00
|
V2: 10.0 HIGH
|
CVE-2000-0438
|
Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.
Published:
May 22, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0453
|
XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.
Published:
May 18, 2000; 12:00:00 AM -04:00
|
V2: 5.0 MEDIUM
|
CVE-2000-0379
|
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.
Published:
May 16, 2000; 12:00:00 AM -04:00
|
V2: 3.6 LOW
|
CVE-2000-0393
|
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.
Published:
May 16, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|
CVE-2000-0378
|
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.
Published:
May 03, 2000; 12:00:00 AM -04:00
|
V2: 7.2 HIGH
|