Next's vulnerability profile centers on a narrow legacy product line spanning operating systems and development environments including NeXTSTEP, OpenStep, and related platforms. The recurring exposure involves memory-safety issues, particularly buffer overflows and input-validation weaknesses characteristic of systems software from that era, and the associated disclosures have frequently acquired public exploit tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Next over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0046HIGH Buffer overflow of rlogin program using TERM environmental variable. | Feb 6, 1997 | 10.0 | 67 | NO | YES |
CVE-1999-0032HIGH Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option. | Oct 25, 1996 | 7.2 | 29 | NO | YES |
CVE-2006-4392HIGH The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process tha | Oct 3, 2006 | 7.2 | 27 | NO | YES |
CVE-1999-1193HIGH The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root. | May 14, 1991 | 10.0 | 25 | NO | NO |
CVE-1999-0956HIGH The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service. | Sep 19, 1997 | 7.2 | 18 | NO | NO |
CVE-1999-1198HIGH BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges. | Oct 3, 1990 | 7.2 | 18 | NO | NO |
CVE-1999-1391HIGH Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions. | Oct 3, 1990 | 7.2 | 18 | NO | NO |
CVE-1999-1392HIGH Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges. | Oct 3, 1990 | 7.2 | 18 | NO | NO |
CVE-1999-1468MEDIUM rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable. | Oct 22, 1991 | 6.2 | 17 | NO | NO |
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. | Apr 18, 1996 | 1.9 | 13 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Next.
Media articles that mention a CVE ID that affects a product developed by Next — matched by CVE ID, not by vendor name.