2.1

CVE-2001-0178

kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.

Data is provided by the National Vulnerability Database (NVD)
ConectivaLinux Version6.0
CalderaOpenlinux Edesktop Version2.4
MandrakesoftMandrake Linux Version6.1
MandrakesoftMandrake Linux Version7.0
MandrakesoftMandrake Linux Version7.1
MandrakesoftMandrake Linux Version7.2
SuseSuse Linux Version6.0
SuseSuse Linux Version6.1
SuseSuse Linux Version6.2
SuseSuse Linux Version6.3
SuseSuse Linux Version6.4
SuseSuse Linux Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.251
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N