Doing

2 exploits Active since Jul 2000
CVE-2000-0666 EXPLOITDB c WORKING POC
rpc.statd - Privilege Escalation
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
CVE-2000-0844 EXPLOITDB c WORKING POC
Caldera Openlinux Ebuilder - Access Control
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.