CVE-2002-1814
- EPSS 0.25%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.
CVE-2002-2001
- EPSS 0.15%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
CVE-2002-2185
- EPSS 0.51%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the ...
CVE-2002-0836
- EPSS 14.13%
- Published 28.10.2002 05:00:00
- Last modified 03.04.2025 01:03:51
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
CVE-2002-0638
- EPSS 0.09%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race con...
- EPSS 2.66%
- Published 15.03.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
CVE-2002-0004
- EPSS 0.27%
- Published 27.02.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
CVE-2002-0002
- EPSS 14.92%
- Published 31.01.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
CVE-2001-1190
- EPSS 0.07%
- Published 12.12.2001 05:00:00
- Last modified 03.04.2025 01:03:51
The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended.
CVE-2001-0912
- EPSS 0.05%
- Published 30.11.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges.