← Vulnerability feed

Vulnerability record · CVE-2000-1096 · published 9 January 2001

CVE-2000-1096: Paul vixie vixie cron vulnerability

PPaul Vixie · Vixie Cron

crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

3.7 CVSS 2.0 Low EPSS 0.79% · top 45.4%
3.7CVSS 2.0 base score
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

AV:L/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-1096 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2006-2607Paul vixie vixie cron vulnerabilitydo_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if…EPSS 0.57%7.2CVE-2001-0559Paul vixie vixie cron vulnerabilitycrontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification operation, which could allow a l…EPSS 1.1%7.2CVE-1999-0872Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.EPSS 0.36%7.2CVE-1999-0769Paul vixie vixie cron vulnerabilityVixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.EPSS 0.80%7.2CVE-1999-0297Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.EPSS 0.40%4.6CVE-2001-0560Paul vixie vixie cron vulnerabilityBuffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long username (> 20 characters).EPSS 0.51%3.3CVE-2010-0424Fedorahosted cronie link following vulnerabilityThe edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of …EPSS 0.35%2.1CVE-2007-1856Paul vixie vixie cron vulnerabilityVixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2000-1096), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.