Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2013-1049
Disclosure Date: March 14, 2013 (last updated October 05, 2023)
Buffer overflow in the RFC1413 (ident) client in cfingerd 1.4.3-3 allows remote IDENT servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted response.
0
Attacker Value
Unknown
CVE-2004-2272
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command.
0
Attacker Value
Unknown
CVE-2004-2273
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error.
0
Attacker Value
Unknown
CVE-2002-2091
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Format string vulnerability in Deception Finger Daemon, decfingerd, 0.7 may allow remote attackers to execute arbitrary code via the username of a finger request.
0
Attacker Value
Unknown
CVE-2002-2244
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle.
0
Attacker Value
Unknown
CVE-2002-2274
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
akfingerd 0.5 allows local users to read arbitrary files as the akfingerd user (nobody) via a symlink attack on the .plan file.
0
Attacker Value
Unknown
CVE-2002-2243
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it.
0
Attacker Value
Unknown
CVE-2002-0424
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.
0
Attacker Value
Unknown
CVE-2002-0423
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup.
0
Attacker Value
Unknown
CVE-2001-0735
Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.
0