- EPSS 1.09%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.
CVE-2000-0916
- EPSS 8.35%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.
CVE-2000-0963
- EPSS 0.16%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
CVE-2000-0993
- EPSS 0.23%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
CVE-2000-0998
- EPSS 0.26%
- Veröffentlicht 11.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function.
CVE-2000-1011
- EPSS 0.05%
- Veröffentlicht 11.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable.
CVE-2000-1012
- EPSS 0.05%
- Veröffentlicht 11.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.
CVE-2000-1013
- EPSS 0.05%
- Veröffentlicht 11.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.
- EPSS 0.74%
- Veröffentlicht 11.12.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.
CVE-2000-0852
- EPSS 0.05%
- Veröffentlicht 14.11.2000 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.