Conectiva Linux vulnerabilities

60 known vulnerabilities affecting conectiva/linux.

Total CVEs
60
CISA KEV
0
Public exploits
17
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH17MEDIUM18LOW10

Vulnerabilities

Page 3 of 3
CVE-2003-0468MEDIUMCVSS 5.0v7.0v8.02003-08-27
CVE-2003-0468 [MEDIUM] CVE-2003-0468: Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.
nvd
CVE-2002-0083CRITICALCVSS 9.8PoCv5.0v5.1+4 more2002-03-15
CVE-2002-0083 [CRITICAL] CWE-193 CVE-2002-0083: Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malic Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
nvd
CVE-2001-0834MEDIUMCVSS 6.4v5.0v5.1+2 more2001-12-06
CVE-2001-0834 [MEDIUM] CVE-2001-0834: htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c opt htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the targ
nvd
CVE-2001-1374HIGHCVSS 7.2v6.0v7.02001-07-19
CVE-2001-1374 [HIGH] CVE-2001-1374: expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allo expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
nvd
CVE-2001-1375MEDIUMCVSS 4.6v6.0v7.02001-07-19
CVE-2001-1375 [MEDIUM] CVE-2001-1375: tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before othe tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.
nvd
CVE-2001-0440HIGHCVSS 7.5PoCv4.0v4.0es+7 more2001-07-02
CVE-2001-0440 [HIGH] CVE-2001-0440: Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.
nvd
CVE-2001-0439HIGHCVSS 7.5v4.0v4.0es+3 more2001-07-02
CVE-2001-0439 [HIGH] CVE-2001-0439: licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
nvd
CVE-2001-0170LOWCVSS 2.1PoCv4.0v4.0es+7 more2001-03-26
CVE-2001-0170 [LOW] CVE-2001-0170: glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS e glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
nvd
CVE-2001-0178LOWCVSS 2.1v6.02001-03-26
CVE-2001-0178 [LOW] CVE-2001-0178: kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
nvd
CVE-2001-0128HIGHCVSS 7.2v4.2v5.0+2 more2001-03-12
CVE-2001-0128 [HIGH] CVE-2001-0128: Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
nvd
CVE-2000-1134HIGHCVSS 7.2PoCv4.0v4.0es+4 more2001-01-09
CVE-2000-1134 [HIGH] CVE-2000-1134: Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
nvd
CVE-2000-1095HIGHCVSS 7.2PoCv5.12001-01-09
CVE-2000-1095 [HIGH] CVE-2000-1095: modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary com modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
nvd
CVE-2000-0844CRITICALCVSS 10.0PoCv4.0v4.0es+4 more2000-11-14
CVE-2000-0844 [CRITICAL] CWE-264 CVE-2000-0844: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected fo Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
nvd
CVE-2000-0747CRITICALCVSS 10.0v4.1v4.2+1 more2000-10-20
CVE-2000-0747 [CRITICAL] CVE-2000-0747: The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the k The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.
nvd
CVE-2000-0701MEDIUMCVSS 4.6v4.1v4.2+2 more2000-10-20
CVE-2000-0701 [MEDIUM] CVE-2000-0701: The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format stri The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
nvd
CVE-2000-0715LOWCVSS 2.1v5.0v5.12000-10-20
CVE-2000-0715 [LOW] CWE-59 CVE-2000-0715: DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitra DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.
nvd
CVE-2000-0668MEDIUMCVSS 5.0PoCv4.0v4.0es+4 more2000-07-27
CVE-2000-0668 [MEDIUM] CVE-2000-0668: pam_console PAM module in Linux systems allows a user to access the system console and reboot the sy pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.
nvd
CVE-2000-0667LOWCVSS 3.6v4.0v4.0es+4 more2000-07-27
CVE-2000-0667 [LOW] CVE-2000-0667: Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a deni Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.
nvd
CVE-2000-0633LOWCVSS 2.1v4.0v4.0es+4 more2000-07-18
CVE-2000-0633 [LOW] CVE-2000-0633: Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system. Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.
nvd
CVE-2000-0666CRITICALCVSS 10.0PoCv4.0v4.0es+4 more2000-07-16
CVE-2000-0666 [CRITICAL] CVE-2000-0666: rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untruste rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
nvd