Vulnerabilities > GNU > Inetutils > High

DATE CVE VULNERABILITY TITLE RISK
2023-08-14 CVE-2023-40303 Unchecked Return Value vulnerability in GNU Inetutils
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd.
local
low complexity
gnu CWE-252
7.8
2022-08-30 CVE-2022-39028 NULL Pointer Dereference vulnerability in multiple products
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8.
network
low complexity
gnu mit debian netkit-telnet-project CWE-476
7.5
2004-12-31 CVE-2004-1485 Remote Buffer Overflow vulnerability in InetUtils TFTP Client
Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.
network
low complexity
gnu tftp
7.5