CVEs (208)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.txt file that contains filenames with shell metacharacters, then causing the file to be searched using...Show more |
kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp. |
4Debian MandrakesoftRalf S. Engelschall+1 more4Debian Linux EperlMandrake Linux+1 moreApr 16, 2026 Jun 27, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands. |
3Freebsd MandrakesoftSuse3Freebsd Mandrake LinuxSuse LinuxApr 16, 2026 Jun 27, 2001 N/A· v4 N/A· v3 10.0 HIGH· v2 time server daemon timed allows remote attackers to cause a denial of service via malformed packets. |
Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter. |
4Caldera ConectivaMandrakesoft+1 more5Linux Mandrake LinuxMandrake Linux Corporate Server+2 moreApr 16, 2026 Mar 26, 2001 N/A· v4 N/A· v3 2.1 LOW· v2 kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges. |
Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name. |
rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file. |
7Caldera ConectivaHp+4 more9Hp Ux ImmunixLinux+6 moreApr 16, 2026 Jan 9, 2001 N/A· v4 N/A· v3 7.2 HIGH· v2 Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to over...Show more |
in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash. |
5Conectiva ImmunixMandrakesoft+2 more5Immunix LinuxLinux+2 moreApr 16, 2026 Jan 9, 2001 N/A· v4 N/A· v3 7.2 HIGH· v2 modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters. |
Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges. |
Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service. |
The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HT...Show more |
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method. |
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/. |
13Caldera ConectivaDebian+10 more16Aix Debian LinuxImmunix+13 moreApr 16, 2026 Nov 14, 2000 N/A· v4 N/A· v3 10.0 HIGH· v2 Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. |
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges. |
5Conectiva DebianRedhat+2 more5Debian Linux LinuxLinux+2 moreApr 16, 2026 Jul 16, 2000 N/A· v4 N/A· v3 10.0 HIGH· v2 rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges. |
Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output. |