Caldera Openlinux vulnerabilities

28 known vulnerabilities affecting caldera/openlinux.

Total CVEs
28
CISA KEV
0
Public exploits
11
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH8MEDIUM8LOW2

Vulnerabilities

Page 1 of 2
CVE-2002-1199MEDIUMCVSS 5.0v2.2v2.3+1 more2002-10-28
CVE-2002-1199 [MEDIUM] CVE-2002-1199: The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to r The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.
nvd
CVE-2001-0850CRITICALCVSS 10.0v3.12001-12-06
CVE-2001-0850 [CRITICAL] CVE-2001-0850: A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow.
nvd
CVE-2001-0851MEDIUMCVSS 5.0v2.32001-12-06
CVE-2001-0851 [MEDIUM] CVE-2001-0851: Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rul Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.
nvd
CVE-2000-0566HIGHCVSS 7.2v2.3v2.42000-07-03
CVE-2000-0566 [HIGH] CVE-2000-0566: makewhatis in Linux man package allows local users to overwrite files via a symlink attack. makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
nvd
CVE-2000-0530HIGHCVSS 7.2PoCv2.42000-05-31
CVE-2000-0530 [HIGH] CVE-2000-0530: The KApplication class in the KDE 1.1.2 configuration file management capability allows local users The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.
nvd
CVE-2000-0438HIGHCVSS 7.2PoCv7.02000-05-22
CVE-2000-0438 [HIGH] CVE-2000-0438: Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbi Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter.
nvd
CVE-2000-0192MEDIUMCVSS 5.0PoCv2.32000-03-05
CVE-2000-0192 [MEDIUM] CVE-2000-0192: The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows r The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.
nvd
CVE-2000-0218HIGHCVSS 7.2PoCv2.32000-02-03
CVE-2000-0218 [HIGH] CVE-2000-0218: Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long rela Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.
nvd
CVE-2000-0531LOWCVSS 2.1PoCv2.3v2.41999-11-23
CVE-2000-0531 [LOW] CVE-2000-0531: Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.
nvd
CVE-2000-0369MEDIUMCVSS 5.0v2.31999-10-08
CVE-2000-0369 [MEDIUM] CVE-2000-0369: The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.
nvd
CVE-1999-0879CRITICALCVSS 10.0PoCv1.01999-10-01
CVE-1999-0879 [CRITICAL] CVE-1999-0879: Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges v Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.
nvd
CVE-1999-0880MEDIUMCVSS 5.0v1.01999-10-01
CVE-1999-0880 [MEDIUM] CVE-1999-0880: Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly. Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.
nvd
CVE-1999-0769HIGHCVSS 7.2PoCv2.21999-08-25
CVE-1999-0769 [HIGH] CVE-1999-0769: Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
nvd
CVE-1999-0872HIGHCVSS 7.2v2.21999-08-25
CVE-1999-0872 [HIGH] CVE-1999-0872: Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment v Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
nvd
CVE-2000-0374CRITICALCVSS 10.0v2.2v2.31999-08-22
CVE-2000-0374 [CRITICAL] CVE-2000-0374: The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, al The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.
nvd
CVE-1999-0731MEDIUMCVSS 4.6v1.3v2.21999-06-23
CVE-1999-0731 [MEDIUM] CVE-1999-0731: The KDE klock program allows local users to unlock a session using malformed input. The KDE klock program allows local users to unlock a session using malformed input.
nvd
CVE-1999-0712LOWCVSS 2.1v2.21999-04-27
CVE-1999-0712 [LOW] CVE-1999-0712: A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.
nvd
CVE-1999-0434HIGHCVSS 7.5v1.21999-03-30
CVE-1999-0434 [HIGH] CVE-1999-0434: XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restr XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
nvd
CVE-1999-0368CRITICALCVSS 10.0PoCv1.31999-02-09
CVE-1999-0368 [CRITICAL] CVE-1999-0368: Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
nvd
CVE-2000-0370CRITICALCVSS 10.0v1.0v1.1+2 more1999-01-29
CVE-2000-0370 [CRITICAL] CVE-2000-0370: The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metach The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.
nvd