Vulnerabilities > GNU > Glibc > 2.1.1

DATE CVE VULNERABILITY TITLE RISK
2003-03-25 CVE-2003-0028 Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
network
low complexity
gnu mit openafs sgi cray freebsd hp ibm openbsd sun
7.5
2002-11-12 CVE-2002-1265 Denial Of Service vulnerability in Multiple Vendor Sun RPC LibC TCP Time-Out
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
network
low complexity
gnu sgi apple
5.0
2002-10-11 CVE-2002-1146 Unspecified vulnerability in GNU Glibc
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
network
low complexity
gnu
5.0
2002-08-12 CVE-2002-0684 Remote Security vulnerability in glibc
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.
network
low complexity
gnu isc
7.5
2000-11-14 CVE-2000-0824 Unspecified vulnerability in GNU Glibc 2.1.1
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.
local
low complexity
gnu
7.2
2000-05-03 CVE-2000-0335 The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
network
low complexity
gnu isc
7.5