Vulnerabilities > Debian > Debian Linux > 3.0

DATE CVE VULNERABILITY TITLE RISK
2004-05-04 CVE-2003-0618 Information Disclosure vulnerability in Suidperl
Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files for which the user does not have appropriate permissions.
local
low complexity
perl debian
2.1
2004-02-16 CVE-2004-1180 Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).
network
low complexity
sun debian mandrakesoft
5.0
2003-08-27 CVE-2003-0615 Cross-Site Scripting vulnerability in CGI.pm Start_Form
Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.
4.3
2003-08-18 CVE-2003-0440 The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
low complexity
semi debian
4.6
2003-07-02 CVE-2003-0382 Buffer Overflow vulnerability in Eterm PATH_ENV
Buffer overflow in Eterm 0.9.2 allows local users to gain privileges via a long ETERMPATH environment variable.
local
low complexity
michael-jennings debian
4.6
2003-07-02 CVE-2003-0367 Improper Input Validation vulnerability in multiple products
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
low complexity
gnu debian CWE-20
2.1
2003-06-09 CVE-2003-0358 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.
local
low complexity
falconseye-project nethack debian CWE-120
4.6
2003-05-15 CVE-2003-0308 Local Security vulnerability in Sendmail
The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privileges via (1) expn, (2) checksendmail, or (3) doublebounce.pl.
local
low complexity
sendmail debian
7.2
2003-03-03 CVE-2003-0098 Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
network
low complexity
apcupsd debian
critical
10.0
2002-12-26 CVE-2002-1372 Unchecked Return Value vulnerability in multiple products
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.
network
low complexity
apple debian CWE-252
7.5