peter bassill · operator
$ cve CVE-2000-0844 JSON

CVE-2000-0844 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 15.6% (pctl 97)

Patch early

A public exploit exists.

Description

Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS15.63% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2000-11-14
Last modified2026-06-16

Affected (16)

VendorProduct
calderaopenlinux
calderaopenlinux ebuilder
calderaopenlinux eserver
conectivalinux
debiandebian linux
ibmaix
immuniximmunix
mandrakesoftmandrake linux
redhatlinux
sgiirix
slackwareslackware linux
sunsolaris
sunsunos
susesuse linux
trustixsecure linux
turbolinuxturbolinux

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD