Known Vulnerabilities for products from Paul Vixie

Listed below are 10 of the newest known vulnerabilities associated with the vendor "Paul Vixie".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2010-0424 The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change th... 3.3 - LOW 2010-02-25 2023-02-13
CVE-2007-1856 Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial ... 2.1 - LOW 2007-04-18 2017-10-11
CVE-2006-2607 do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to... 7.2 - HIGH 2006-05-25 2018-10-18
CVE-2005-1038 crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by chang... 2.1 - LOW 2005-05-02 2017-10-11
CVE-2001-0560 Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long user... 4.6 - MEDIUM 2001-08-22 2017-10-10
CVE-2001-0559 crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operatio... 7.2 - HIGH 2001-08-14 2017-10-10
CVE-2000-1096 crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by... 3.7 - LOW 2001-01-09 2018-05-03
CVE-1999-0872 Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file... 7.2 - HIGH 1999-08-25 2008-09-09
CVE-1999-0769 Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable. 7.2 - HIGH 1999-08-25 2008-09-09
CVE-1999-0297 Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental var... 7.2 - HIGH 1996-12-12 2022-08-17