| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2000-0112 |
The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation. Published: February 02, 2000; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
| CVE-2000-0107 |
Linux apcd program allows local attackers to modify arbitrary files via a symlink attack. Published: February 01, 2000; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
| CVE-2000-1221 |
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP. Published: January 08, 2000; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-1999-1330 |
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf. Published: December 31, 1999; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 4.6 MEDIUM |
| CVE-2000-0076 |
nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover. Published: December 30, 1999; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-1999-0978 |
htdig allows remote attackers to execute commands via filenames with shell metacharacters. Published: December 09, 1999; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
| CVE-1999-0986 |
The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option. Published: December 08, 1999; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-2000-0366 |
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files. Published: December 02, 1999; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-1999-0831 |
Denial of service in Linux syslogd via a large number of connections. Published: November 19, 1999; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-1999-0832 |
Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname. Published: November 09, 1999; 12:00:00 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-1999-0939 |
Denial of service in Debian IRC Epic/epic4 client via a long string. Published: August 26, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-1999-0769 |
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable. Published: August 25, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 7.2 HIGH |
| CVE-1999-0872 |
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. Published: August 25, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 7.2 HIGH |
| CVE-1999-0743 |
Trn allows local users to overwrite other users' files via symlinks. Published: August 20, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-1999-1565 |
Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. Published: August 20, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 4.6 MEDIUM |
| CVE-1999-0732 |
The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links. Published: August 19, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-1999-0742 |
The Debian mailman package uses weak authentication, which allows attackers to gain privileges. Published: June 22, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
| CVE-1999-0730 |
The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack. Published: June 12, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 10.0 HIGH |
| CVE-1999-1496 |
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist. Published: June 08, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-1999-0804 |
Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths. Published: June 01, 1999; 12:00:00 AM -0400 |
V3.x:(not available) V2.0: 5.0 MEDIUM |