Vulnerabilities > ISC > INN > 1.5.1

DATE CVE VULNERABILITY TITLE RISK
2012-11-11 CVE-2012-3523 Permissions, Privileges, and Access Controls vulnerability in ISC INN
The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
network
isc CWE-264
6.8
2000-10-20 CVE-2000-0360 Unspecified vulnerability in ISC INN
Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.
network
low complexity
isc
5.0
2000-04-27 CVE-1999-0706 Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.
network
low complexity
isc redhat
7.5
1997-07-21 CVE-1999-0247 Unspecified vulnerability in ISC INN
Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.
network
low complexity
isc
7.5
1997-02-20 CVE-1999-0868 ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.
local
low complexity
isc netscape sun redhat nec
7.2
1997-01-01 CVE-1999-0100 Unspecified vulnerability in ISC INN 1.5.1
Remote access in AIX innd 1.5.1, using control messages.
network
low complexity
isc
critical
10.0