CVE-2003-0859
- EPSS 0.37%
- Veröffentlicht 15.12.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:03:05
The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
CVE-2003-0028
- EPSS 15.03%
- Veröffentlicht 25.03.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:01:22
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via ...
- EPSS 2.5%
- Veröffentlicht 12.11.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:59:01
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
- EPSS 3.28%
- Veröffentlicht 11.10.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:58:48
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to rea...
CVE-2002-0684
- EPSS 5.86%
- Veröffentlicht 12.08.2002 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:57:56
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by func...
CVE-2000-0959
- EPSS 0.3%
- Veröffentlicht 19.12.2000 05:00:00
- Zuletzt bearbeitet 23.09.2026 13:10:00
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
CVE-2000-0824
- EPSS 1.23%
- Veröffentlicht 14.11.2000 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:52:32
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate en...
CVE-2000-0335
- EPSS 1.59%
- Veröffentlicht 03.05.2000 04:00:00
- Zuletzt bearbeitet 16.06.2026 21:51:30
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.