Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
📦
openlinux_ebuilder
Vendor: caldera
Actively Exploited
0
CISA KEV List
PoC / Exploits
3
Code Available
Total RCEs
0
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
32.58%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
10.0
CVSS
CVE-2000-0917
Exploit Found
Severity: HIGH
10.0
CVSS
CVE-2000-0844
Exploit Found
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
Severity: HIGH
5.0
CVSS
CVE-2000-0594
Exploit Found
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.
Severity: MEDIUM