Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2003-1324

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.
0
Attacker Value
Unknown

CVE-2003-1323

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Elm ME+ 2.4 before PL109S, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group via unspecified vectors.
0
Attacker Value
Unknown

CVE-1999-1334

Disclosure Date: December 31, 1999 (last updated February 22, 2025)
Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.
0
Attacker Value
Unknown

CVE-1999-0114

Disclosure Date: January 01, 1998 (last updated February 22, 2025)
Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.
0