Home/Product/caldera openlinux
Product

caldera openlinux

36 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2002-1199
all versions
The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp,
CVE-2001-0851
all versions
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the
CVE-2001-0850
all versions
A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which
CVE-2000-0892
all versions
Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive inform
CVE-2000-1134
all versions
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processin
CVE-2000-0917
all versions
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
CVE-2000-0844
all versions
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows loc
CVE-2000-0372
all versions
Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.
CVE-2000-0566
all versions
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
CVE-2000-0530
all versions
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.
CVE-2000-0491
all versions
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or
CVE-2000-0438
all versions
Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long moun
CVE-2000-0192
all versions
The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine w
CVE-2000-0218
all versions
Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.
CVE-2000-0531
all versions
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.
CVE-2000-0369
all versions
The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a de
CVE-1999-0880
all versions
Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.
CVE-1999-0879
all versions
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a messag
CVE-1999-0872
all versions
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
CVE-1999-0769
all versions
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
CVE-2000-0374
all versions
The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from an
CVE-1999-0731
all versions
The KDE klock program allows local users to unlock a session using malformed input.
CVE-1999-0712
all versions
A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.
CVE-1999-0439
all versions
Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmai
CVE-1999-0434
all versions
XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly al
CVE-1999-0368
all versions
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
CVE-2000-0370
all versions
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for
CVE-1999-1288
all versions
Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the
CVE-1999-0002
all versions
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
CVE-1999-0009
all versions
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
CVE-1999-0104
all versions
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
CVE-1999-0017
all versions
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
CVE-1999-0042
all versions
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
CVE-1999-0047
all versions
MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.
CVE-1999-0043
all versions
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
9.8CRITICAL
CVE-1999-0234
all versions
Bash treats any character with a value of 255 as a command separator.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin