VYPR

Vendor CVEs

Red Hat

All CVEs

6,458 total · sorted by risk
  • CVE-2000-0618Jun 22, 2000
    risk 0.00cvss —epss 0.00

    Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.

  • CVE-2000-0606Jun 21, 2000
    risk 0.00cvss —epss 0.01

    Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.

  • CVE-2000-0604Jun 21, 2000
    risk 0.00cvss —epss 0.00

    gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.

  • CVE-2000-0602Jun 21, 2000
    risk 0.00cvss —epss 0.00

    Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.

  • CVE-2000-0483Jun 15, 2000
    risk 0.00cvss —epss 0.03

    The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.

  • CVE-2000-0391May 16, 2000
    risk 0.00cvss —epss 0.04

    Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.

  • CVE-2000-0392May 16, 2000
    risk 0.00cvss —epss 0.00

    Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.

  • CVE-2000-0390May 16, 2000
    risk 0.00cvss —epss 0.04

    Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.

  • CVE-1999-0706Apr 27, 2000
    risk 0.00cvss —epss 0.02

    Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.

  • CVE-2000-0289Mar 27, 2000
    risk 0.00cvss —epss 0.03

    IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.

  • CVE-2000-0184Mar 9, 2000
    risk 0.00cvss —epss 0.00

    Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.

  • CVE-2000-0186Feb 28, 2000
    risk 0.00cvss —epss 0.00

    Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.

  • CVE-2000-0196Feb 28, 2000
    risk 0.00cvss —epss 0.03

    Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.

  • CVE-2000-0093Jan 21, 2000
    risk 0.00cvss —epss 0.01

    An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.

  • CVE-1999-0894Jan 4, 2000
    risk 0.00cvss —epss 0.02

    Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.

  • CVE-1999-1328Dec 31, 1999
    risk 0.00cvss —epss 0.00

    linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.

  • CVE-1999-1329Dec 31, 1999
    risk 0.00cvss —epss 0.00

    Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.

  • CVE-1999-1331Dec 31, 1999
    risk 0.00cvss —epss 0.00

    netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.

  • CVE-1999-1330Dec 31, 1999
    risk 0.00cvss —epss 0.00

    The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.

  • CVE-1999-1332Dec 31, 1999
    risk 0.00cvss —epss 0.00

    gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.

  • CVE-1999-1335Dec 31, 1999
    risk 0.00cvss —epss 0.02

    snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.

  • CVE-1999-1333Dec 31, 1999
    risk 0.00cvss —epss 0.03

    automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.

  • CVE-1999-1327Dec 31, 1999
    risk 0.00cvss —epss 0.00

    Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.

  • CVE-2000-0358Dec 3, 1999
    risk 0.00cvss —epss 0.02

    ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.

  • CVE-2000-0357Dec 3, 1999
    risk 0.00cvss —epss 0.02

    ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.

  • CVE-1999-0832Nov 9, 1999
    risk 0.00cvss —epss 0.03

    Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.

  • CVE-2000-0356Oct 13, 1999
    risk 0.00cvss —epss 0.00

    Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.

  • CVE-1999-1347Oct 7, 1999
    risk 0.00cvss —epss 0.00

    Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.

  • CVE-1999-1346Oct 7, 1999
    risk 0.00cvss —epss 0.02

    PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.

  • CVE-1999-1542Oct 4, 1999
    risk 0.00cvss —epss 0.03

    RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the "MAIL FROM" command.

  • CVE-1999-0872Aug 25, 1999
    risk 0.00cvss —epss 0.00

    Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.

  • CVE-2000-0355Aug 21, 1999
    risk 0.00cvss —epss 0.01

    pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.

  • CVE-1999-0740Aug 19, 1999
    risk 0.00cvss —epss 0.02

    Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.

  • CVE-1999-0814Aug 11, 1999
    risk 0.00cvss —epss 0.02

    Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.

  • CVE-1999-1348Jun 30, 1999
    risk 0.00cvss —epss 0.00

    Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.

  • CVE-1999-0748Jun 24, 1999
    risk 0.00cvss —epss 0.02

    Buffer overflows in Red Hat net-tools package.

  • CVE-1999-1496Jun 8, 1999
    risk 0.00cvss —epss 0.01

    Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.

  • CVE-2000-0364Jun 1, 1999
    risk 0.00cvss —epss 0.00

    screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.

  • CVE-2000-0365Jun 1, 1999
    risk 0.00cvss —epss 0.00

    Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.

  • CVE-1999-0434Mar 30, 1999
    risk 0.00cvss —epss 0.01

    XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.

  • CVE-1999-0390Jan 4, 1999
    risk 0.00cvss —epss 0.00

    Buffer overflow in Dosemu Slang library in Linux.

  • CVE-1999-0798Dec 4, 1998
    risk 0.00cvss —epss 0.02

    Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.

  • CVE-1999-1288Nov 19, 1998
    risk 0.00cvss —epss 0.00

    Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.

  • CVE-1999-1048Sep 5, 1998
    risk 0.00cvss —epss 0.01

    Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that…

  • CVE-1999-1406Jul 29, 1998
    risk 0.00cvss —epss 0.00

    dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

  • CVE-1999-0010Apr 8, 1998
    risk 0.00cvss —epss 0.02

    Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

  • CVE-1999-1407Mar 9, 1998
    risk 0.00cvss —epss 0.00

    ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

  • CVE-1999-1095Oct 6, 1997
    risk 0.00cvss —epss 0.00

    sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.

  • CVE-1999-1182Jul 17, 1997
    risk 0.00cvss —epss 0.00

    Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.

  • CVE-1999-0037May 21, 1997
    risk 0.00cvss —epss 0.04

    Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.

Page 129 of 130