VYPR

Vendor CVEs

Red Hat

All CVEs

6,363 total · sorted by risk
  • CVE-2000-1213Oct 18, 2000
    risk 0.00cvss epss 0.02

    ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.

  • CVE-2000-1214Oct 18, 2000
    risk 0.00cvss epss 0.00

    Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.

  • CVE-2000-1207Sep 30, 2000
    risk 0.00cvss epss 0.00

    userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables…

  • CVE-2000-0633Jul 18, 2000
    risk 0.00cvss epss 0.00

    Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.

  • CVE-2000-0566Jul 3, 2000
    risk 0.00cvss epss 0.00

    makewhatis in Linux man package allows local users to overwrite files via a symlink attack.

  • CVE-2000-0618Jun 22, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.

  • CVE-2000-0604Jun 21, 2000
    risk 0.00cvss epss 0.00

    gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.

  • CVE-2000-0602Jun 21, 2000
    risk 0.00cvss epss 0.00

    Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.

  • CVE-2000-0606Jun 21, 2000
    risk 0.00cvss epss 0.01

    Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.

  • CVE-2000-0483Jun 15, 2000
    risk 0.00cvss epss 0.03

    The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.

  • CVE-2000-0392May 16, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.

  • CVE-2000-0391May 16, 2000
    risk 0.00cvss epss 0.04

    Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.

  • CVE-2000-0390May 16, 2000
    risk 0.00cvss epss 0.04

    Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.

  • CVE-1999-0706Apr 27, 2000
    risk 0.00cvss epss 0.02

    Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.

  • CVE-2000-0289Mar 27, 2000
    risk 0.00cvss epss 0.03

    IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.

  • CVE-2000-0184Mar 9, 2000
    risk 0.00cvss epss 0.00

    Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.

  • CVE-2000-0196Feb 28, 2000
    risk 0.00cvss epss 0.03

    Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.

  • CVE-2000-0186Feb 28, 2000
    risk 0.00cvss epss 0.00

    Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.

  • CVE-2000-0093Jan 21, 2000
    risk 0.00cvss epss 0.01

    An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.

  • CVE-1999-0894Jan 4, 2000
    risk 0.00cvss epss 0.02

    Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.

  • CVE-1999-1335Dec 31, 1999
    risk 0.00cvss epss 0.02

    snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.

  • CVE-1999-1328Dec 31, 1999
    risk 0.00cvss epss 0.00

    linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.

  • CVE-1999-1329Dec 31, 1999
    risk 0.00cvss epss 0.00

    Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.

  • CVE-1999-1330Dec 31, 1999
    risk 0.00cvss epss 0.00

    The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.

  • CVE-1999-1332Dec 31, 1999
    risk 0.00cvss epss 0.00

    gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.

  • CVE-1999-1333Dec 31, 1999
    risk 0.00cvss epss 0.03

    automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.

  • CVE-1999-1331Dec 31, 1999
    risk 0.00cvss epss 0.00

    netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.

  • CVE-1999-1327Dec 31, 1999
    risk 0.00cvss epss 0.00

    Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.

  • CVE-2000-0358Dec 3, 1999
    risk 0.00cvss epss 0.02

    ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.

  • CVE-2000-0357Dec 3, 1999
    risk 0.00cvss epss 0.02

    ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.

  • CVE-1999-0832Nov 9, 1999
    risk 0.00cvss epss 0.03

    Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.

  • CVE-2000-0356Oct 13, 1999
    risk 0.00cvss epss 0.00

    Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.

  • CVE-1999-1346Oct 7, 1999
    risk 0.00cvss epss 0.01

    PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.

  • CVE-1999-1347Oct 7, 1999
    risk 0.00cvss epss 0.00

    Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.

  • CVE-1999-1542Oct 4, 1999
    risk 0.00cvss epss 0.03

    RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the "MAIL FROM" command.

  • CVE-1999-0872Aug 25, 1999
    risk 0.00cvss epss 0.00

    Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.

  • CVE-2000-0355Aug 21, 1999
    risk 0.00cvss epss 0.01

    pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.

  • CVE-1999-0740Aug 19, 1999
    risk 0.00cvss epss 0.02

    Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.

  • CVE-1999-0814Aug 11, 1999
    risk 0.00cvss epss 0.02

    Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.

  • CVE-1999-1348Jun 30, 1999
    risk 0.00cvss epss 0.00

    Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.

  • CVE-1999-0748Jun 24, 1999
    risk 0.00cvss epss 0.01

    Buffer overflows in Red Hat net-tools package.

  • CVE-1999-1496Jun 8, 1999
    risk 0.00cvss epss 0.01

    Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.

  • CVE-2000-0364Jun 1, 1999
    risk 0.00cvss epss 0.00

    screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.

  • CVE-2000-0365Jun 1, 1999
    risk 0.00cvss epss 0.00

    Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.

  • CVE-1999-0434Mar 30, 1999
    risk 0.00cvss epss 0.01

    XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.

  • CVE-1999-0390Jan 4, 1999
    risk 0.00cvss epss 0.00

    Buffer overflow in Dosemu Slang library in Linux.

  • CVE-1999-0798Dec 4, 1998
    risk 0.00cvss epss 0.02

    Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.

  • CVE-1999-1288Nov 19, 1998
    risk 0.00cvss epss 0.00

    Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.

  • CVE-1999-1048Sep 5, 1998
    risk 0.00cvss epss 0.01

    Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that…

  • CVE-1999-1406Jul 29, 1998
    risk 0.00cvss epss 0.00

    dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

Page 127 of 128