Search: "debian"

239 CVEs found

cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and a...

Published: 1996-07-16
Products: 12
Vendors:
ubuntu redhat mandrakesoft debian freebsd

suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.

Published: 1998-04-28
Products: 1
Vendors:
debian

The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such...

Published: 1998-11-26
Products: 1
Vendors:
debian
CVE-1999-0698
10.0 HIGH

Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.

Published: 1999-01-01
Products: 0

Buffer overflow in the bootp server in the Debian Linux netstd package.

Published: 1999-01-03
Products: 5
Vendors:
debian

Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.

Published: 1999-01-03
Products: 5
Vendors:
debian
CVE-1999-0678
5.0 MEDIUM

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

Published: 1999-01-17
Products: 2
Vendors:
apache debian

Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.

Published: 1999-02-01
Products: 1
Vendors:
debian

Debian GNU/Linux cfengine package is susceptible to a symlink attack.

Published: 1999-02-16
Products: 1
Vendors:
debian

Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.

Published: 1999-02-18
Products: 1
Vendors:
michael_jennings

Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different err...

Published: 1999-06-08
Products: 3
Vendors:
todd_miller debian redhat
CVE-1999-0730
10.0 HIGH

The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.

Published: 1999-06-12
Products: 1
Vendors:
debian
CVE-1999-0742
5.0 MEDIUM

The Debian mailman package uses weak authentication, which allows attackers to gain privileges.

Published: 1999-06-22
Products: 1
Vendors:
debian

The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.

Published: 1999-08-19
Products: 1
Vendors:
debian
CVE-1999-0939
5.0 MEDIUM

Denial of service in Debian IRC Epic/epic4 client via a long string.

Published: 1999-08-26
Products: 2
Vendors:
debian

dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.

Published: 1999-12-02
Products: 1
Vendors:
debian

nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.

Published: 1999-12-30
Products: 2
Vendors:
debian berkeley

The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.

Published: 2000-02-02
Products: 5
Vendors:
debian

The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.

Published: 2000-02-05
Products: 1
Vendors:
debian
CVE-2000-1135
4.6 MEDIUM

fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.

Published: 2001-01-09
Products: 2
Vendors:
debian