📦

inn

Vendor: inn

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 2 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 4.51% Exploit Prob.
Latest CVE CVE-2021-31998 Jun 10

Security Vulnerability Index

Page 1 / 1
6.8 CVSS

A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root. This issue affects: SUSE Linux Enterprise Server 11-SP3 inn version inn-2.4.2-170.21.3.1 and prior versions. openSUSE Backports SLE-15-SP2 inn versions prior to 2.6.2. openSUSE Leap 15.2 inn versions prior to 2.6.2.

EPSS: 0.03%
7.7 CVSS

The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn version 2.4.2-170.21.3.1 and prior versions. openSUSE Factory inn version 2.6.2-2.2 and prior versions. openSUSE Leap 15.1 inn version 2.5.4-lp151.2.47 and prior versions.

EPSS: 0.17%
6.8 CVSS

The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.

EPSS: 18.81%
7.5 CVSS

Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote attackers to execute arbitrary code.

EPSS: 31.03%
7.2 CVSS

Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls.

EPSS: 0.07%
10.0 CVSS
CVE-2002-0525
Exploit Found

Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.

EPSS: 4.35%
4.6 CVSS
CVE-2001-1442
Exploit Found

Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privileges via a long -c command line argument.

EPSS: 0.44%
5.0 CVSS

Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.

EPSS: 1.29%
7.5 CVSS

Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.

EPSS: 0.86%
3.6 CVSS
CVE-2000-0472
Exploit Found

Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.

EPSS: 4.93%