CVE-1999-0046
Buffer overflow of rlogin program using TERM environmental variable.
Affects 10 products across 10 vendors.
Program copies data to a buffer without verifying the source data fits within the destination.
A critical buffer overflow vulnerability exists in the rlogin program when handling the TERM environmental variable, which could allow an attacker to execute arbitrary code with the privileges of the user running rlogin.
BSID: BS-1997-GLOBAL-307597-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-1999-0046?
What is the CVSS score for CVE-1999-0046?
Is CVE-1999-0046 actively exploited?
How do I remediate CVE-1999-0046?
What systems are affected by CVE-1999-0046?
| CVE ID | CVE-1999-0046 |
|---|---|
| BSID | BS-1997-GLOBAL-307597-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 1997-02-06 |
| Last Modified | 2026-04-16 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
Buffer overflow of rlogin program using TERM environmental variable.
Source: NIST NVD / MITRE CVE Database
The vulnerability is exploited by setting a specially crafted TERM environmental variable with a length exceeding the buffer size allocated for it in the rlogin program. This can overwrite adjacent memory, potentially leading to arbitrary code execution.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Bsdi | Bsd Os | — |
| Debian | Debian Linux | — |
| Digital | Ultrix | — |
| Freebsd | Freebsd | — |
| Hp | Hp-Ux | — |
| Ibm | Aix | — |
| Netbsd | Netbsd | — |
| Next | Nextstep | — |
| Oracle | Solaris | — |
| Sun | Sunos | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →