Home/Product/next
Product

next

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2018-17137
all versions
Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might
9.8CRITICAL
CVE-2018-7467
all versions
AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.
7.5HIGH
CVE-2006-4392
all versions
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local
CVE-1999-0956
all versions
The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.
CVE-1999-0046
all versions
Buffer overflow of rlogin program using TERM environmental variable.
CVE-1999-0032
all versions
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a l
CVE-1999-0078
all versions
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC
CVE-1999-1468
all versions
rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IF
CVE-1999-1193
<= 2.1
The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to
CVE-1999-1392
all versions
Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.
CVE-1999-1391
all versions
Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of th
CVE-1999-1198
<= 2.0
BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root pr
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin