- EPSS 89.66%
- Veröffentlicht 28.09.2014 19:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted use of here doc...
- EPSS 85.13%
- Veröffentlicht 27.09.2014 22:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-poin...
- EPSS 90.11%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
CVE-2012-3410
- EPSS 0.08%
- Veröffentlicht 27.08.2012 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd, which is not properly handled when expanding the /dev/fd prefix.
CVE-2010-0002
- EPSS 0.33%
- Veröffentlicht 14.01.2010 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the ex...
CVE-1999-0491
- EPSS 0.3%
- Veröffentlicht 20.04.1999 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
CVE-1999-1383
- EPSS 0.06%
- Veröffentlicht 13.09.1996 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands file...