CVE-1999-1572
cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and a...
mandrakesoft ubuntu redhat freebsd debian
CVE-1999-0202
The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.
university_of_washington
CVE-1999-1411
The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such...
debian
CVE-1999-0914
Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
debian
CVE-1999-0678
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
apache debian
CVE-1999-0373
Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.
debian
CVE-1999-0374
Debian GNU/Linux cfengine package is susceptible to a symlink attack.
debian
CVE-2000-0367
Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.
michael_jennings
CVE-1999-0409
Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.
suse
CVE-1999-1165
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) re...
gnu
CVE-1999-0719
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
gnu
CVE-2000-0366
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
debian
CVE-2000-0151
GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.
gnu
CVE-2000-0112
The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.
debian
CVE-2000-0145
The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.
debian
CVE-2000-0786
GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access re...
gnu
CVE-2000-0803
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description fi...
gnu
CVE-2000-0947
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
gnu
CVE-2000-0974
GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.
gnu
CVE-2000-1135
fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.
debian