Skip to main content

Vendor/product archive

gnu / inetutils CVEs

Beta · best-effort

9 CVEs tagged to gnu / inetutils3 Critical, 4 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2026-32772

Published Mar 16, 2026

telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32746

Published Mar 13, 2026

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer i…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-28372

Published Feb 27, 2026

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-…

CVSS 7.4 · High
evidence mentions
9
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-24061

Published Jan 21, 2026

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

CVSS 9.8 · Critical
evidence mentions
23
Buzz score
88.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-40303

Published Aug 14, 2023

GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for ex…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40491

Published Sep 3, 2021

The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4862

Published Dec 25, 2011

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2004-1485

Published Dec 31, 2004

Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1