Netkit
2 CVEs tracked since 2002. Since Mar 2002, none of them reached CISA KEV.
Netkit CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2002-03 | 1 | 0 |
| 2002-04 | null or fewer | |
| 2002-05 | null or fewer | |
| 2002-06 | null or fewer | |
| 2002-07 | null or fewer | |
| 2002-08 | null or fewer | |
| 2002-09 | null or fewer | |
| 2002-10 | null or fewer | |
| 2002-11 | null or fewer | |
| 2002-12 | null or fewer | |
| 2003-01 | null or fewer | |
| 2003-02 | null or fewer | |
| 2003-03 | null or fewer | |
| 2003-04 | null or fewer | |
| 2003-05 | null or fewer | |
| 2003-06 | null or fewer | |
| 2003-07 | null or fewer | |
| 2003-08 | null or fewer | |
| 2003-09 | null or fewer | |
| 2003-10 | null or fewer | |
| 2003-11 | null or fewer | |
| 2003-12 | null or fewer | |
| 2004-01 | null or fewer | |
| 2004-02 | null or fewer | |
| 2004-03 | null or fewer | |
| 2004-04 | null or fewer | |
| 2004-05 | null or fewer | |
| 2004-06 | null or fewer | |
| 2004-07 | 1 | 0 |
Products
The products that kept showing up in Netkit's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 7 most recently published vulnerabilities affecting Netkit.
- CVE-2023-38336netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.9.8
- CVE-2019-7283An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validat...7.4
- CVE-2019-7282In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions ...5.9
- CVE-2006-6008ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to g...6.5
- CVE-2005-0178Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking,...6.2
- CVE-2004-0640Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.10.0
- CVE-2001-0554Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is no...10.0
The record
- Peak rank
- #58 in Jul 2004
- Busiest month shown
- Mar 2002, 1 CVEs
- Months with a KEV entry
- 0 since Mar 2002
- Monthly snapshots
- 2 since 2002