Vendor CVEs
Debian
All CVEs
10,468 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2003-0120 | 0.00 | — | 0.00 | Mar 7, 2003 | adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name. | |||
| CVE-2003-0098 | 0.00 | — | 0.05 | Mar 3, 2003 | Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server. | |||
| CVE-2002-1395 | 0.00 | — | 0.00 | Jan 17, 2003 | Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz. | |||
| CVE-2002-2185 | 0.00 | — | 0.02 | Dec 31, 2002 | The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively… | |||
| CVE-2002-1232 | 0.00 | — | 0.03 | Nov 4, 2002 | Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist. | |||
| CVE-2002-0839 | 0.00 | — | 0.01 | Oct 11, 2002 | The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be… | |||
| CVE-2002-0910 | 0.00 | — | 0.03 | Oct 4, 2002 | Buffer overflows in netstd 3.07-17 package allows remote DNS servers to execute arbitrary code via a long FQDN reply, as observed in the utilities (1) linux-ftpd, (2) pcnfsd, (3) tftp, (4) traceroute, or (5) from/to. | |||
| CVE-2002-0912 | 0.00 | — | 0.03 | Oct 4, 2002 | in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote attackers to cause a denial of service, possibly due to a buffer overflow. | |||
| CVE-2002-0062 | 0.00 | — | 0.00 | Mar 8, 2002 | Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling." | |||
| CVE-2002-0044 | 0.00 | — | 0.00 | Jan 31, 2002 | GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files. | |||
| CVE-2001-0886 | 0.00 | — | 0.01 | Dec 21, 2001 | Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character. | |||
| CVE-2001-0834 | 0.00 | — | 0.03 | Dec 6, 2001 | htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read… | |||
| CVE-2001-0755 | 0.00 | — | 0.02 | Oct 18, 2001 | Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a long SITE command. | |||
| CVE-2001-0738 | 0.00 | — | 0.03 | Oct 18, 2001 | LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes to be placed in log messages. | |||
| CVE-2001-0977 | 0.00 | — | 0.04 | Jul 16, 2001 | slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field. | |||
| CVE-2001-0430 | 0.00 | — | 0.00 | Jul 2, 2001 | Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files. | |||
| CVE-2001-0416 | 0.00 | — | 0.00 | Jun 27, 2001 | sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools. | |||
| CVE-2001-0456 | 0.00 | — | 0.06 | Jun 27, 2001 | postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended. | |||
| CVE-2001-0457 | 0.00 | — | 0.02 | Jun 27, 2001 | man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion). | |||
| CVE-2001-0441 | 0.00 | — | 0.03 | Jun 27, 2001 | Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header. | |||
| CVE-2001-0458 | 0.00 | — | 0.02 | Jun 27, 2001 | Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands. | |||
| CVE-2001-1331 | 0.00 | — | 0.00 | May 3, 2001 | mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks. | |||
| CVE-2001-0235 | 0.00 | — | 0.00 | Mar 26, 2001 | Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running. | |||
| CVE-2001-0128 | 0.00 | — | 0.00 | Mar 12, 2001 | Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges. | |||
| CVE-2000-0315 | 0.00 | — | 0.02 | Mar 12, 2001 | traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks. | |||
| CVE-2000-0314 | 0.00 | — | 0.02 | Mar 12, 2001 | traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero. | |||
| CVE-2001-0139 | 0.00 | — | 0.00 | Mar 12, 2001 | inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. | |||
| CVE-2001-0125 | 0.00 | — | 0.00 | Mar 12, 2001 | exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file. | |||
| CVE-2001-0131 | 0.00 | — | 0.02 | Mar 12, 2001 | htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. | |||
| CVE-2001-0138 | 0.00 | — | 0.00 | Mar 12, 2001 | privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack. | |||
| CVE-2001-0069 | 0.00 | — | 0.00 | Feb 12, 2001 | dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack. | |||
| CVE-2000-1135 | 0.00 | — | 0.00 | Jan 9, 2001 | fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack. | |||
| CVE-2000-1136 | 0.00 | — | 0.00 | Jan 9, 2001 | elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack. | |||
| CVE-2000-0867 | 0.00 | — | 0.00 | Nov 14, 2000 | Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages. | |||
| CVE-2000-0511 | 0.00 | — | 0.02 | Jun 21, 2000 | CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request. | |||
| CVE-2000-0606 | 0.00 | — | 0.01 | Jun 21, 2000 | Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter. | |||
| CVE-2000-0510 | 0.00 | — | 0.02 | Jun 21, 2000 | CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request. | |||
| CVE-2000-0513 | 0.00 | — | 0.02 | Jun 21, 2000 | CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password. | |||
| CVE-2000-0512 | 0.00 | — | 0.02 | Jun 16, 2000 | CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service. | |||
| CVE-2000-0289 | 0.00 | — | 0.03 | Mar 27, 2000 | IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection. | |||
| CVE-2000-0145 | 0.00 | — | 0.02 | Feb 5, 2000 | The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions. | |||
| CVE-2000-0112 | 0.00 | — | 0.00 | Feb 2, 2000 | The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation. | |||
| CVE-1999-1330 | 0.00 | — | 0.00 | Dec 31, 1999 | The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf. | |||
| CVE-2000-0076 | 0.00 | — | 0.00 | Dec 30, 1999 | nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover. | |||
| CVE-1999-0978 | 0.00 | — | 0.02 | Dec 9, 1999 | htdig allows remote attackers to execute commands via filenames with shell metacharacters. | |||
| CVE-2000-0366 | 0.00 | — | 0.00 | Dec 2, 1999 | dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files. | |||
| CVE-1999-0831 | 0.00 | — | 0.01 | Nov 19, 1999 | Denial of service in Linux syslogd via a large number of connections. | |||
| CVE-1999-0832 | 0.00 | — | 0.03 | Nov 9, 1999 | Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname. | |||
| CVE-1999-0939 | 0.00 | — | 0.01 | Aug 26, 1999 | Denial of service in Debian IRC Epic/epic4 client via a long string. | |||
| CVE-1999-0872 | 0.00 | — | 0.00 | Aug 25, 1999 | Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. |
- CVE-2003-0120Mar 7, 2003risk 0.00cvss —epss 0.00
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.
- CVE-2003-0098Mar 3, 2003risk 0.00cvss —epss 0.05
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
- CVE-2002-1395Jan 17, 2003risk 0.00cvss —epss 0.00
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via immknmz.
- CVE-2002-2185Dec 31, 2002risk 0.00cvss —epss 0.02
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively…
- CVE-2002-1232Nov 4, 2002risk 0.00cvss —epss 0.03
Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
- CVE-2002-0839Oct 11, 2002risk 0.00cvss —epss 0.01
The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be…
- CVE-2002-0910Oct 4, 2002risk 0.00cvss —epss 0.03
Buffer overflows in netstd 3.07-17 package allows remote DNS servers to execute arbitrary code via a long FQDN reply, as observed in the utilities (1) linux-ftpd, (2) pcnfsd, (3) tftp, (4) traceroute, or (5) from/to.
- CVE-2002-0912Oct 4, 2002risk 0.00cvss —epss 0.03
in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote attackers to cause a denial of service, possibly due to a buffer overflow.
- CVE-2002-0062Mar 8, 2002risk 0.00cvss —epss 0.00
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
- CVE-2002-0044Jan 31, 2002risk 0.00cvss —epss 0.00
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
- CVE-2001-0886Dec 21, 2001risk 0.00cvss —epss 0.01
Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character.
- CVE-2001-0834Dec 6, 2001risk 0.00cvss —epss 0.03
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read…
- CVE-2001-0755Oct 18, 2001risk 0.00cvss —epss 0.02
Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a long SITE command.
- CVE-2001-0738Oct 18, 2001risk 0.00cvss —epss 0.03
LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes to be placed in log messages.
- CVE-2001-0977Jul 16, 2001risk 0.00cvss —epss 0.04
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
- CVE-2001-0430Jul 2, 2001risk 0.00cvss —epss 0.00
Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.
- CVE-2001-0416Jun 27, 2001risk 0.00cvss —epss 0.00
sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.
- CVE-2001-0456Jun 27, 2001risk 0.00cvss —epss 0.06
postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.
- CVE-2001-0457Jun 27, 2001risk 0.00cvss —epss 0.02
man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion).
- CVE-2001-0441Jun 27, 2001risk 0.00cvss —epss 0.03
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
- CVE-2001-0458Jun 27, 2001risk 0.00cvss —epss 0.02
Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.
- CVE-2001-1331May 3, 2001risk 0.00cvss —epss 0.00
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.
- CVE-2001-0235Mar 26, 2001risk 0.00cvss —epss 0.00
Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running.
- CVE-2001-0128Mar 12, 2001risk 0.00cvss —epss 0.00
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
- CVE-2000-0315Mar 12, 2001risk 0.00cvss —epss 0.02
traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
- CVE-2000-0314Mar 12, 2001risk 0.00cvss —epss 0.02
traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.
- CVE-2001-0139Mar 12, 2001risk 0.00cvss —epss 0.00
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
- CVE-2001-0125Mar 12, 2001risk 0.00cvss —epss 0.00
exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.
- CVE-2001-0131Mar 12, 2001risk 0.00cvss —epss 0.02
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2001-0138Mar 12, 2001risk 0.00cvss —epss 0.00
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2001-0069Feb 12, 2001risk 0.00cvss —epss 0.00
dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2000-1135Jan 9, 2001risk 0.00cvss —epss 0.00
fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.
- CVE-2000-1136Jan 9, 2001risk 0.00cvss —epss 0.00
elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.
- CVE-2000-0867Nov 14, 2000risk 0.00cvss —epss 0.00
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
- CVE-2000-0511Jun 21, 2000risk 0.00cvss —epss 0.02
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request.
- CVE-2000-0606Jun 21, 2000risk 0.00cvss —epss 0.01
Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.
- CVE-2000-0510Jun 21, 2000risk 0.00cvss —epss 0.02
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request.
- CVE-2000-0513Jun 21, 2000risk 0.00cvss —epss 0.02
CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password.
- CVE-2000-0512Jun 16, 2000risk 0.00cvss —epss 0.02
CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.
- CVE-2000-0289Mar 27, 2000risk 0.00cvss —epss 0.03
IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.
- CVE-2000-0145Feb 5, 2000risk 0.00cvss —epss 0.02
The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.
- CVE-2000-0112Feb 2, 2000risk 0.00cvss —epss 0.00
The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.
- CVE-1999-1330Dec 31, 1999risk 0.00cvss —epss 0.00
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
- CVE-2000-0076Dec 30, 1999risk 0.00cvss —epss 0.00
nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.
- CVE-1999-0978Dec 9, 1999risk 0.00cvss —epss 0.02
htdig allows remote attackers to execute commands via filenames with shell metacharacters.
- CVE-2000-0366Dec 2, 1999risk 0.00cvss —epss 0.00
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
- CVE-1999-0831Nov 19, 1999risk 0.00cvss —epss 0.01
Denial of service in Linux syslogd via a large number of connections.
- CVE-1999-0832Nov 9, 1999risk 0.00cvss —epss 0.03
Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.
- CVE-1999-0939Aug 26, 1999risk 0.00cvss —epss 0.01
Denial of service in Debian IRC Epic/epic4 client via a long string.
- CVE-1999-0872Aug 25, 1999risk 0.00cvss —epss 0.00
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
Page 209 of 210