← Vulnerability feed

Vulnerability record · CVE-1999-0043 · published 4 December 1996

CVE-1999-0043: Isc inn os command injection vulnerability

Isc · Inn

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

9.8 CVSS 3.1 Critical EPSS 45% · top 1.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-0043 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2002-0525Isc inn vulnerabilityFormat string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privile…EPSS 4.1%10.0CVE-2001-0850Caldera openlinux vulnerabilityA configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local …EPSS 2.3%10.0CVE-2000-0917LPRng use_syslog format string allows remote command executionLPRng 3.6.24 contains a format string vulnerability in the use_syslog() function. Because the flaw is remotely reachable and leads to arbitrary comma…EPSS 79%analysed10.0CVE-2000-0844Caldera openlinux ebuilder permissions and access controls vulnerabilitySome functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to exec…EPSS 16%10.0CVE-2000-0491Gnome gdm vulnerabilityBuffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of s…EPSS 18%10.0CVE-1999-0879Bsdi bsd os vulnerabilityBuffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.EPSS 9.7%10.0CVE-2000-0374Caldera openlinux vulnerabilityThe default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allow…EPSS 4.3%10.0CVE-1999-0754Isc inn vulnerabilityThe INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variabl…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-1999-0043), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.