Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-24890

Disclosure Date: March 25, 2024 (last updated April 02, 2024)
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/gala-gopher/blob/master/src/probes/extends/ebpf.Probe/src/ioprobe/ioprobe.C. This issue affects gala-gopher: through 1.0.2.
0
Attacker Value
Unknown

CVE-2019-9738

Disclosure Date: March 13, 2019 (last updated November 27, 2024)
jimmykuu Gopher 2.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
0
Attacker Value
Unknown

CVE-2005-2772

Disclosure Date: September 02, 2005 (last updated February 22, 2025)
Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.
0
Attacker Value
Unknown

CVE-2005-1853

Disclosure Date: August 03, 2005 (last updated February 22, 2025)
gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.
0
Attacker Value
Unknown

CVE-2004-0560

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted content of a certain size that triggers the overflow.
0
Attacker Value
Unknown

CVE-2004-0561

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
0
Attacker Value
Unknown

CVE-2003-0805

Disclosure Date: October 06, 2003 (last updated February 22, 2025)
Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.
0
Attacker Value
Unknown

CVE-2002-0371

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
0
Attacker Value
Unknown

CVE-2000-0743

Disclosure Date: October 20, 2000 (last updated February 22, 2025)
Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.
0
Attacker Value
Unknown

CVE-1999-0124

Disclosure Date: August 09, 1993 (last updated February 22, 2025)
Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.
0