← Back

Cfingerd

cfingerd

Vendor: Infodrom • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Infodrom
1Cfingerd
Apr 16, 2026
Oct 18, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.
1Infodrom
1Cfingerd
Apr 16, 2026
Aug 2, 2001
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.
1Infodrom
1Cfingerd
Apr 16, 2026
Sep 21, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.
1Infodrom
1Cfingerd
Apr 16, 2026
Aug 10, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
1Infodrom
1Cfingerd
Apr 16, 2026
May 23, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
cfingerd lists all users on a system via search.**@target.