7.2

CVE-2000-0118

The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.

Data is provided by the National Vulnerability Database (NVD)
RedhatLinux Version2.0
RedhatLinux Version2.1
RedhatLinux Version3.0.3
RedhatLinux Version4.0
RedhatLinux Version4.1
RedhatLinux Version4.2
RedhatLinux Version5.0
RedhatLinux Version5.1
RedhatLinux Version5.2 Editionalpha
RedhatLinux Version5.2 Editioni386
RedhatLinux Version5.2 Editionsparc
RedhatLinux Version6.0 Editionalpha
RedhatLinux Version6.0 Editioni386
RedhatLinux Version6.0 Editionsparc
RedhatLinux Version6.1 Editionalpha
RedhatLinux Version6.1 Editioni386
RedhatLinux Version6.1 Editionsparc
SunSolaris Editionx86
SunSolaris Version1.1.3 Updateu1
SunSolaris Version1.1.4 Editionjl
SunSolaris Version2.4 Editionx86
SunSunos Version-
SunSunos Version4.1.3
SunSunos Version4.1.4
SunSunos Version5.0
SunSunos Version5.1
SunSunos Version5.2
SunSunos Version5.3
SunSunos Version5.4
SunSunos Version5.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.318
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C