CVE-2010-0015
- EPSS 1.82%
- Published 14.01.2010 18:30:00
- Last modified 09.04.2025 00:30:58
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords o...
CVE-2004-0968
- EPSS 0.07%
- Published 09.02.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
CVE-2004-1382
- EPSS 0.09%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
CVE-2004-1453
- EPSS 0.08%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the...
CVE-2003-0859
- EPSS 0.05%
- Published 15.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
CVE-2003-0028
- EPSS 56.05%
- Published 25.03.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via ...
- EPSS 2.37%
- Published 12.11.2002 05:00:00
- Last modified 03.04.2025 01:03:51
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
- EPSS 9.72%
- Published 11.10.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to rea...
CVE-2002-0684
- EPSS 3.54%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by func...
CVE-2000-0959
- EPSS 0.09%
- Published 19.12.2000 05:00:00
- Last modified 03.04.2025 01:03:51
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.