Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Unknown
CVE-2014-7169
Disclosure Date: September 25, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
0
Attacker Value
Unknown
CVE-2009-0115
Disclosure Date: March 30, 2009 (last updated February 17, 2024)
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.
0
Attacker Value
Unknown
CVE-2001-0134
Disclosure Date: March 12, 2001 (last updated February 22, 2025)
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
0
Attacker Value
Unknown
CVE-1999-1185
Disclosure Date: October 06, 1998 (last updated February 22, 2025)
Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.
0
Attacker Value
Unknown
CVE-1999-0009
Disclosure Date: April 08, 1998 (last updated February 22, 2025)
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
0
Attacker Value
Unknown
CVE-1999-0011
Disclosure Date: April 08, 1998 (last updated February 22, 2025)
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
0
Attacker Value
Unknown
CVE-1999-0010
Disclosure Date: April 08, 1998 (last updated February 22, 2025)
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
0
Attacker Value
Unknown
CVE-1999-0017
Disclosure Date: December 10, 1997 (last updated February 22, 2025)
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
0
Attacker Value
Unknown
CVE-1999-1209
Disclosure Date: November 20, 1997 (last updated February 22, 2025)
Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.
0