Search: "gnu"

1221 CVEs found

cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and a...

Published: 1996-07-16
Products: 12
Vendors:
mandrakesoft ubuntu redhat freebsd debian

The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.

Published: 1997-01-01
Products: 1
Vendors:
university_of_washington

The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such...

Published: 1998-11-26
Products: 1
Vendors:
debian

Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.

Published: 1999-01-03
Products: 5
Vendors:
debian
CVE-1999-0678
5.0 MEDIUM

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

Published: 1999-01-17
Products: 2
Vendors:
apache debian

Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.

Published: 1999-02-01
Products: 1
Vendors:
debian

Debian GNU/Linux cfengine package is susceptible to a symlink attack.

Published: 1999-02-16
Products: 1
Vendors:
debian

Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.

Published: 1999-02-18
Products: 1
Vendors:
michael_jennings
CVE-1999-0409
4.6 MEDIUM

Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.

Published: 1999-03-04
Products: 2
Vendors:
suse

GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) re...

Published: 1999-07-21
Products: 1
Vendors:
gnu
CVE-1999-0719
4.6 MEDIUM

The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.

Published: 1999-08-05
Products: 1
Vendors:
gnu

dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.

Published: 1999-12-02
Products: 1
Vendors:
debian
CVE-2000-0151
6.2 MEDIUM

GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.

Published: 2000-02-01
Products: 1
Vendors:
gnu

The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.

Published: 2000-02-02
Products: 5
Vendors:
debian

The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.

Published: 2000-02-05
Products: 1
Vendors:
debian
CVE-2000-0786
4.6 MEDIUM

GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access re...

Published: 2000-10-20
Products: 1
Vendors:
gnu
CVE-2000-0803
10.0 HIGH

GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description fi...

Published: 2000-12-19
Products: 1
Vendors:
gnu
CVE-2000-0947
10.0 HIGH

Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.

Published: 2000-12-19
Products: 3
Vendors:
gnu

GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.

Published: 2000-12-19
Products: 4
Vendors:
gnu
CVE-2000-1135
4.6 MEDIUM

fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.

Published: 2001-01-09
Products: 2
Vendors:
debian