CVE-1999-0046

CRITICAL ⚠ Exploit

Buffer overflow of rlogin program using TERM environmental variable.

Affects 10 products across 10 vendors.

BCS8.83
CVSS 2.010.0
EPSS51.9%
Percentile99th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-120: Buffer Copy without Checking Size (Classic Buffer Overflow)

Program copies data to a buffer without verifying the source data fits within the destination.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical buffer overflow vulnerability exists in the rlogin program when handling the TERM environmental variable, which could allow an attacker to execute arbitrary code with the privileges of the user running rlogin.

BSID: BS-1997-GLOBAL-307597-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-1999-0046?
A critical buffer overflow vulnerability exists in the rlogin program when handling the TERM environmental variable, which could allow an attacker to execute arbitrary code with the privileges of the user running rlogin.
What is the CVSS score for CVE-1999-0046?
CVE-1999-0046 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 51.9%.
Is CVE-1999-0046 actively exploited?
Public exploit available for CVE-1999-0046. Exploitation risk elevated.
How do I remediate CVE-1999-0046?
Priority: IMMEDIATE.
What systems are affected by CVE-1999-0046?
CVE-1999-0046 affects: Bsdi, Debian, Digital, Freebsd, Hp, Ibm, Netbsd, Next.
Vulnerability Details
CVE IDCVE-1999-0046
BSIDBS-1997-GLOBAL-307597-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published1997-02-06
Last Modified2026-04-16
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Buffer overflow of rlogin program using TERM environmental variable.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by setting a specially crafted TERM environmental variable with a length exceeding the buffer size allocated for it in the rlogin program. This can overwrite adjacent memory, potentially leading to arbitrary code execution.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Bsdi Bsd Os
Debian Debian Linux
Digital Ultrix
Freebsd Freebsd
Hp Hp-Ux
Ibm Aix
Netbsd Netbsd
Next Nextstep
Oracle Solaris
Sun Sunos
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 10755 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Bsdi
CVE-1999-0042 10.0 Buffer overflow in University of Washington's implementation of IMAP and POP servers. CVE-1999-0165 10.0 NFS cache poisoning. CVE-1999-0099 10.0 Buffer overflow in syslog utility allows local or remote attackers to gain ro... CVE-1999-0047 10.0 MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. CVE-1999-0323 10.0 FreeBSD mmap function allows users to modify append-only or immutable files.
View all Bsdi CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →