Vulnerabilities > GNU > Cfengine > Critical

DATE CVE VULNERABILITY TITLE RISK
2004-08-09 CVE-2004-1701 Remote Heap Based Buffer Overrun vulnerability in GNU CFEngine AuthenticationDialogue
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.
network
low complexity
gnu
critical
10.0
2000-12-19 CVE-2000-0947 Unspecified vulnerability in GNU Cfengine 1.5/1.5.34/1.6
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
network
low complexity
gnu
critical
10.0