| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0946 | 0.00 | — | 0.00 | Dec 19, 2000 | Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization. | |||
| CVE-2000-0947 | 0.00 | — | 0.01 | Dec 19, 2000 | Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command. | |||
| CVE-2000-0948 | 0.00 | — | 0.00 | Dec 19, 2000 | GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack. | |||
| CVE-2000-0949 | 0.03 | — | 0.00 | Dec 19, 2000 | Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option. | |||
| CVE-2000-0950 | 0.00 | — | 0.00 | Dec 19, 2000 | Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name. | |||
| CVE-2000-0951 | 0.07 | — | 0.49 | Dec 19, 2000 | A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search. | |||
| CVE-2000-0952 | 0.00 | — | 0.02 | Dec 19, 2000 | global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters. | |||
| CVE-2000-0953 | 0.03 | — | 0.06 | Dec 19, 2000 | Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection. | |||
| CVE-2000-0954 | 0.00 | — | 0.00 | Dec 19, 2000 | Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server. | |||
| CVE-2000-0955 | 0.04 | — | 0.07 | Dec 19, 2000 | Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges. | |||
| CVE-2000-0956 | 0.00 | — | 0.00 | Dec 19, 2000 | cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions. | |||
| CVE-2000-0957 | 0.00 | — | 0.00 | Dec 19, 2000 | The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes. | |||
| CVE-2000-0958 | 0.03 | — | 0.06 | Dec 19, 2000 | HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window. | |||
| CVE-2000-0959 | 0.00 | — | 0.00 | Dec 19, 2000 | glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack. | |||
| CVE-2000-0960 | 0.00 | — | 0.01 | Dec 19, 2000 | The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse. | |||
| CVE-2000-0961 | 0.00 | — | 0.01 | Dec 19, 2000 | Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command. | |||
| CVE-2000-0962 | 0.00 | — | 0.01 | Dec 19, 2000 | The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service. | |||
| CVE-2000-0963 | 0.00 | — | 0.00 | Dec 19, 2000 | Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS. | |||
| CVE-2000-0964 | 0.00 | — | 0.02 | Dec 19, 2000 | Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request. | |||
| CVE-2000-0965 | 0.00 | — | 0.01 | Dec 19, 2000 | The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization). | |||
| CVE-2000-0966 | 0.00 | — | 0.00 | Dec 19, 2000 | Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges. | |||
| CVE-2000-0967 | 0.05 | — | 0.27 | Dec 19, 2000 | PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs. | |||
| CVE-2000-0968 | 0.00 | — | 0.03 | Dec 19, 2000 | Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command. | |||
| CVE-2000-0969 | 0.00 | — | 0.03 | Dec 19, 2000 | Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon. | |||
| CVE-2000-0970 | 0.03 | — | 0.38 | Dec 19, 2000 | IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability. | |||
| CVE-2000-0971 | 0.04 | — | 0.12 | Dec 19, 2000 | Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command. | |||
| CVE-2000-0972 | Med | 0.39 | 5.5 | 0.02 | Dec 19, 2000 | HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates. | ||
| CVE-2000-0973 | 0.04 | — | 0.12 | Dec 19, 2000 | Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated. | |||
| CVE-2000-0974 | 0.00 | — | 0.02 | Dec 19, 2000 | GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection. | |||
| CVE-2000-0975 | 0.04 | — | 0.07 | Dec 19, 2000 | Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-2000-0976 | 0.03 | — | 0.01 | Dec 19, 2000 | Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter. | |||
| CVE-2000-0977 | 0.03 | — | 0.04 | Dec 19, 2000 | mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter. | |||
| CVE-2000-0978 | — | 0.00 | — | 0.01 | Dec 19, 2000 | bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter. | ||
| CVE-2000-0979 | 0.04 | — | 0.12 | Dec 19, 2000 | File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability. | |||
| CVE-2000-0980 | 0.01 | — | 0.07 | Dec 19, 2000 | NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network. | |||
| CVE-2000-0981 | 0.00 | — | 0.01 | Dec 19, 2000 | MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password. | |||
| CVE-2000-0982 | 0.01 | — | 0.10 | Dec 19, 2000 | Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability. | |||
| CVE-2000-0983 | 0.05 | — | 0.23 | Dec 19, 2000 | Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability. | |||
| CVE-2000-0984 | 0.06 | — | 0.40 | Dec 19, 2000 | The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string. | |||
| CVE-2000-0985 | 0.03 | — | 0.06 | Dec 19, 2000 | Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command. | |||
| CVE-2000-0986 | 0.00 | — | 0.00 | Dec 19, 2000 | Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable. | |||
| CVE-2000-0987 | 0.03 | — | 0.00 | Dec 19, 2000 | Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter. | |||
| CVE-2000-0988 | 0.00 | — | 0.01 | Dec 19, 2000 | WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration. | |||
| CVE-2000-0989 | 0.04 | — | 0.12 | Dec 19, 2000 | Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username. | |||
| CVE-2000-0990 | 0.00 | — | 0.01 | Dec 19, 2000 | cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username. | |||
| CVE-2000-0991 | 0.04 | — | 0.09 | Dec 19, 2000 | Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability. | |||
| CVE-2000-0992 | 0.03 | — | 0.03 | Dec 19, 2000 | Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack. | |||
| CVE-2000-0993 | 0.03 | — | 0.00 | Dec 19, 2000 | Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd. | |||
| CVE-2000-0994 | 0.03 | — | 0.00 | Dec 19, 2000 | Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable. | |||
| CVE-2000-0995 | 0.00 | — | 0.00 | Dec 19, 2000 | Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name. |
- CVE-2000-0946Dec 19, 2000risk 0.00cvss —epss 0.00
Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization.
- CVE-2000-0947Dec 19, 2000risk 0.00cvss —epss 0.01
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
- CVE-2000-0948Dec 19, 2000risk 0.00cvss —epss 0.00
GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.
- CVE-2000-0949Dec 19, 2000risk 0.03cvss —epss 0.00
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
- CVE-2000-0950Dec 19, 2000risk 0.00cvss —epss 0.00
Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.
- CVE-2000-0951Dec 19, 2000risk 0.07cvss —epss 0.49
A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.
- CVE-2000-0952Dec 19, 2000risk 0.00cvss —epss 0.02
global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.
- CVE-2000-0953Dec 19, 2000risk 0.03cvss —epss 0.06
Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.
- CVE-2000-0954Dec 19, 2000risk 0.00cvss —epss 0.00
Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.
- CVE-2000-0955Dec 19, 2000risk 0.04cvss —epss 0.07
Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.
- CVE-2000-0956Dec 19, 2000risk 0.00cvss —epss 0.00
cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.
- CVE-2000-0957Dec 19, 2000risk 0.00cvss —epss 0.00
The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.
- CVE-2000-0958Dec 19, 2000risk 0.03cvss —epss 0.06
HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.
- CVE-2000-0959Dec 19, 2000risk 0.00cvss —epss 0.00
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
- CVE-2000-0960Dec 19, 2000risk 0.00cvss —epss 0.01
The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.
- CVE-2000-0961Dec 19, 2000risk 0.00cvss —epss 0.01
Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.
- CVE-2000-0962Dec 19, 2000risk 0.00cvss —epss 0.01
The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.
- CVE-2000-0963Dec 19, 2000risk 0.00cvss —epss 0.00
Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
- CVE-2000-0964Dec 19, 2000risk 0.00cvss —epss 0.02
Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
- CVE-2000-0965Dec 19, 2000risk 0.00cvss —epss 0.01
The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).
- CVE-2000-0966Dec 19, 2000risk 0.00cvss —epss 0.00
Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.
- CVE-2000-0967Dec 19, 2000risk 0.05cvss —epss 0.27
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
- CVE-2000-0968Dec 19, 2000risk 0.00cvss —epss 0.03
Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.
- CVE-2000-0969Dec 19, 2000risk 0.00cvss —epss 0.03
Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.
- CVE-2000-0970Dec 19, 2000risk 0.03cvss —epss 0.38
IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vulnerability.
- CVE-2000-0971Dec 19, 2000risk 0.04cvss —epss 0.12
Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.
- risk 0.39cvss 5.5epss 0.02
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.
- CVE-2000-0973Dec 19, 2000risk 0.04cvss —epss 0.12
Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.
- CVE-2000-0974Dec 19, 2000risk 0.00cvss —epss 0.02
GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.
- CVE-2000-0975Dec 19, 2000risk 0.04cvss —epss 0.07
Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-2000-0976Dec 19, 2000risk 0.03cvss —epss 0.01
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.
- CVE-2000-0977Dec 19, 2000risk 0.03cvss —epss 0.04
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the "filename" parameter in a POST request, which is then sent by email to the address specified in the "email" parameter.
- CVE-2000-0978Dec 19, 2000risk 0.00cvss —epss 0.01
bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the "&" shell metacharacter.
- CVE-2000-0979Dec 19, 2000risk 0.04cvss —epss 0.12
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.
- CVE-2000-0980Dec 19, 2000risk 0.01cvss —epss 0.07
NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.
- CVE-2000-0981Dec 19, 2000risk 0.00cvss —epss 0.01
MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
- CVE-2000-0982Dec 19, 2000risk 0.01cvss —epss 0.10
Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the "Cached Web Credentials" vulnerability.
- CVE-2000-0983Dec 19, 2000risk 0.05cvss —epss 0.23
Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.
- CVE-2000-0984Dec 19, 2000risk 0.06cvss —epss 0.40
The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.
- CVE-2000-0985Dec 19, 2000risk 0.03cvss —epss 0.06
Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.
- CVE-2000-0986Dec 19, 2000risk 0.00cvss —epss 0.00
Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.
- CVE-2000-0987Dec 19, 2000risk 0.03cvss —epss 0.00
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.
- CVE-2000-0988Dec 19, 2000risk 0.00cvss —epss 0.01
WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.
- CVE-2000-0989Dec 19, 2000risk 0.04cvss —epss 0.12
Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.
- CVE-2000-0990Dec 19, 2000risk 0.00cvss —epss 0.01
cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an "SMTP AUTH" command with an unknown username.
- CVE-2000-0991Dec 19, 2000risk 0.04cvss —epss 0.09
Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the "HyperTerminal Buffer Overflow" vulnerability.
- CVE-2000-0992Dec 19, 2000risk 0.03cvss —epss 0.03
Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.
- CVE-2000-0993Dec 19, 2000risk 0.03cvss —epss 0.00
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
- CVE-2000-0994Dec 19, 2000risk 0.03cvss —epss 0.00
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
- CVE-2000-0995Dec 19, 2000risk 0.00cvss —epss 0.00
Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.