VYPR
Vendor

Netkit

Products
4
CVEs
8
Across products
9
Status
Private

Products

4

Recent CVEs

8
  • CVE-2001-0554Aug 14, 2001
    risk 0.06cvss epss 0.38

    Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

  • CVE-2019-7282Jan 31, 2019
    risk 0.00cvss epss 0.02

    In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

  • CVE-2019-7283Jan 31, 2019
    risk 0.00cvss epss 0.02

    An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle…

  • CVE-2007-6263Dec 6, 2007
    risk 0.00cvss epss 0.02

    The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have…

  • CVE-2006-6008Nov 21, 2006
    risk 0.00cvss epss 0.02

    ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to gain privileges if these calls fail in cases such as PAM failures or resource…

  • CVE-2005-0178Mar 7, 2005
    risk 0.00cvss epss 0.00

    Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.

  • CVE-2004-0911Nov 3, 2004
    risk 0.00cvss epss 0.03

    telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554.

  • CVE-2004-0640Aug 6, 2004
    risk 0.00cvss epss 0.04

    Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.