Vulnerabilities (CVE)

Filtered by vendor Gnu Subscribe
Total 1065 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0959 1 Gnu 1 Glibc 2024-02-28 1.2 LOW N/A
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
CVE-2001-1267 1 Gnu 1 Tar 2024-02-28 2.1 LOW N/A
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
CVE-1999-1383 2 Gnu, Tcsh 2 Bash, Tcsh 2024-02-28 4.6 MEDIUM N/A
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.
CVE-1999-0150 1 Gnu 1 Fingerd 2024-02-28 7.5 HIGH N/A
The Perl fingerd program allows arbitrary command execution from remote users.
CVE-2003-1232 1 Gnu 1 Emacs 2024-02-28 5.1 MEDIUM N/A
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.
CVE-2004-0778 1 Gnu 1 Cvs 2024-02-28 5.0 MEDIUM N/A
CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.
CVE-2000-1219 1 Gnu 2 G\+\+, Gcc 2024-02-28 7.5 HIGH N/A
The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.
CVE-2001-1301 2 Gnu, Xemacs 2 Emacs, Xemacs 2024-02-28 1.2 LOW N/A
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
CVE-2004-0581 2 Gnu, Mandrakesoft 3 Ksymoops, Mandrake Linux, Mandrake Linux Corporate Server 2024-02-28 4.6 MEDIUM N/A
ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.
CVE-2003-0991 2 Gnu, Sgi 2 Mailman, Propack 2024-02-28 5.0 MEDIUM N/A
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.
CVE-2002-2099 1 Gnu 1 Data Display Debugger 2024-02-28 7.2 HIGH N/A
Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE.
CVE-2001-1228 1 Gnu 1 Gzip 2024-02-28 7.5 HIGH N/A
Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.
CVE-1999-0016 6 Cisco, Gnu, Hp and 3 more 8 Ios, Inet, Hp-ux and 5 more 2024-02-28 5.0 MEDIUM N/A
Land IP denial of service.
CVE-2004-1485 2 Gnu, Tftp 2 Inetutils, Tftp 2024-02-28 7.5 HIGH N/A
Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.
CVE-2004-1773 1 Gnu 1 Sharutils 2024-02-28 7.5 HIGH N/A
Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
CVE-2004-1186 1 Gnu 1 Enscript 2024-02-28 5.0 MEDIUM N/A
Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
CVE-2004-0131 1 Gnu 1 Radius 2024-02-28 5.0 MEDIUM N/A
The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.
CVE-1999-0612 2 Gnu, Microsoft 4 Finger Service, Fingerd, Windows 2000 and 1 more 2024-02-28 N/A N/A
A version of finger is running that exposes valid user information to any entity on the network.
CVE-2001-0522 1 Gnu 1 Privacy Guard 2024-02-28 7.5 HIGH N/A
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
CVE-2001-1036 2 Gnu, Slackware 2 Findutils, Slackware Linux 2024-02-28 7.2 HIGH N/A
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.