gentoo CVE Vulnerabilities & Metrics

Focus on gentoo vulnerabilities and metrics.

Last updated: 29 Jun 2025, 22:25 UTC

About gentoo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with gentoo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total gentoo CVEs: 13
Earliest CVE date: 07 Mar 2003, 05:00 UTC
Latest CVE date: 15 Jan 2025, 15:15 UTC

Latest CVE reference: CVE-2024-12084

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 4

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 33.33%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 33.33%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical gentoo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.89

Max CVSS: 10.0

Critical CVEs (≥9): 31

CVSS Range vs. Count

Range Count
0.0-3.9 40
4.0-6.9 61
7.0-8.9 44
9.0-10.0 31

CVSS Distribution Chart

Top 5 Highest CVSS gentoo CVEs

These are the five CVEs with the highest CVSS scores for gentoo, sorted by severity first and recency.

All CVEs for gentoo

CVE-2024-12084 gentoo vulnerability CVSS: 0 15 Jan 2025, 15:15 UTC

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer.

CVE-2024-12088 gentoo vulnerability CVSS: 0 14 Jan 2025, 18:15 UTC

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVE-2024-12087 gentoo vulnerability CVSS: 0 14 Jan 2025, 18:15 UTC

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification coupled with deduplication checks occurring on a per-file-list basis could allow a server to write files outside of the client's intended destination directory. A malicious server could write malicious files to arbitrary locations named after valid directories/paths on the client.

CVE-2024-12086 gentoo vulnerability CVSS: 0 14 Jan 2025, 18:15 UTC

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.

CVE-2020-36770 gentoo vulnerability CVSS: 0 15 Jan 2024, 07:15 UTC

pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to become the owner of root-owned files.

CVE-2016-20021 gentoo vulnerability CVSS: 0 12 Jan 2024, 03:15 UTC

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.

CVE-2023-48795 gentoo vulnerability CVSS: 0 18 Dec 2023, 16:15 UTC

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.

CVE-2023-28424 gentoo vulnerability CVSS: 0 20 Mar 2023, 13:15 UTC

Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, unauthenticated attackers can execute arbitrary SQL queries on `https://packages.gentoo.org/`. It was also demonstrated that primitive was enough to gain code execution in the context of the PostgreSQL container. The issue was addressed in commit `4fa6e4b619c0362728955b6ec56eab0e0cbf1e23y` of version 1.0.2 using prepared statements to interpolate user-controlled data in SQL queries.

CVE-2023-26033 gentoo vulnerability CVSS: 0 25 Feb 2023, 00:15 UTC

Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injection, leading to a Denial of Service. If the user selects (in user preferences) the "Recently Visited Packages" view for the index page, the value of the `search_history` cookie is used as a base64 encoded comma separated list of atoms. These are string loaded directly into the SQL query with `atom = '%s'` format string. As a result, any user can modify the browser's cookie value and inject most SQL queries. A proof of concept malformed cookie was generated that wiped the database or changed it's content. On the database, only public data is stored, so there is no confidentiality issues to site users. If it is known that the database was modified, a full restoration of data is possible by performing a full database wipe and performing full update of all components. This issue is patched with commit id 5ae9ca83b73. Version 1.0.1 contains the patch. If users are unable to upgrade immediately, the following workarounds may be applied: (1.) Use a proxy to always drop the `search_history` cookie until upgraded. The impact on user experience is low. (2.) Sanitize to the value of `search_history` cookie after base64 decoding it.

CVE-2019-20384 gentoo vulnerability CVSS: 2.1 21 Jan 2020, 00:15 UTC

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.

CVE-2017-14484 gentoo vulnerability CVSS: 6.9 15 Sep 2017, 10:29 UTC

The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/lib/gimps, because an unsafe "chown -R" command is executed.

CVE-2004-2778 gentoo vulnerability CVSS: 3.6 27 Jun 2017, 20:29 UTC

Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to restricted directories or execute restricted commands via navigating to the affected directories, or executing the affected commands.

CVE-2014-9622 gentoo vulnerability CVSS: 6.8 21 Jan 2015, 18:59 UTC

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.

CVE-2013-2100 gentoo vulnerability CVSS: 9.3 29 Sep 2014, 22:55 UTC

The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify binary package lists via a crafted certificate.

CVE-2014-4909 gentoo vulnerability CVSS: 6.8 29 Jul 2014, 14:55 UTC

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.

CVE-2013-4223 gentoo vulnerability CVSS: 5.0 23 May 2014, 14:55 UTC

The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.

CVE-2013-0348 gentoo vulnerability CVSS: 2.1 13 Dec 2013, 18:07 UTC

thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.

CVE-2013-2032 gentoo vulnerability CVSS: 5.0 18 Nov 2013, 02:55 UTC

MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.

CVE-2013-2031 gentoo vulnerability CVSS: 4.3 18 Nov 2013, 02:55 UTC

MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is then incorrectly interpreted as UTF-8 by Chrome and Firefox.

CVE-2010-1159 gentoo vulnerability CVSS: 6.8 28 Oct 2013, 22:55 UTC

Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL packet.

CVE-2012-4893 gentoo vulnerability CVSS: 6.8 11 Sep 2012, 19:55 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.

CVE-2012-2983 gentoo vulnerability CVSS: 5.0 11 Sep 2012, 18:55 UTC

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.

CVE-2012-2982 gentoo vulnerability CVSS: 6.5 11 Sep 2012, 18:55 UTC

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.

CVE-2012-2981 gentoo vulnerability CVSS: 6.0 11 Sep 2012, 18:55 UTC

Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.

CVE-2011-1550 gentoo vulnerability CVSS: 6.3 30 Mar 2011, 22:55 UTC

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories for the (1) cobbler, (2) inn, (3) safte-monitor, and (4) uucp packages.

CVE-2011-1549 gentoo vulnerability CVSS: 6.3 30 Mar 2011, 22:55 UTC

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.

CVE-2011-1548 gentoo vulnerability CVSS: 6.3 30 Mar 2011, 22:55 UTC

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.

CVE-2011-1155 gentoo vulnerability CVSS: 1.9 30 Mar 2011, 22:55 UTC

The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

CVE-2011-1154 gentoo vulnerability CVSS: 6.9 30 Mar 2011, 22:55 UTC

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

CVE-2011-1098 gentoo vulnerability CVSS: 1.9 30 Mar 2011, 22:55 UTC

Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.

CVE-2008-4580 gentoo vulnerability CVSS: 7.2 15 Oct 2008, 20:08 UTC

fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.

CVE-2008-4579 gentoo vulnerability CVSS: 1.9 15 Oct 2008, 20:08 UTC

The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.

CVE-2008-4394 gentoo vulnerability CVSS: 6.9 10 Oct 2008, 10:30 UTC

Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.

CVE-2008-1734 gentoo vulnerability CVSS: 3.6 18 Apr 2008, 15:05 UTC

Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.

CVE-2008-1383 gentoo vulnerability CVSS: 1.9 18 Mar 2008, 22:44 UTC

The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.

CVE-2008-1078 gentoo vulnerability CVSS: 7.2 29 Feb 2008, 02:44 UTC

expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.

CVE-2008-0386 gentoo vulnerability CVSS: 6.8 04 Feb 2008, 23:00 UTC

Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.

CVE-2007-6249 gentoo vulnerability CVSS: 2.1 15 Dec 2007, 01:46 UTC

etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.

CVE-2007-5714 gentoo vulnerability CVSS: 6.8 30 Oct 2007, 19:46 UTC

The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.

CVE-2007-3531 gentoo vulnerability CVSS: 6.6 25 Jul 2007, 17:30 UTC

The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file.

CVE-2007-3508 gentoo vulnerability CVSS: 7.2 03 Jul 2007, 21:30 UTC

Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution

CVE-2007-2194 gentoo vulnerability CVSS: 10.0 24 Apr 2007, 17:19 UTC

Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.

CVE-2007-2026 gentoo vulnerability CVSS: 7.8 13 Apr 2007, 18:19 UTC

The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.

CVE-2007-1500 gentoo vulnerability CVSS: 4.3 19 Mar 2007, 22:19 UTC

The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.

CVE-2007-0476 gentoo vulnerability CVSS: 4.6 25 Jan 2007, 00:28 UTC

The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.

CVE-2006-3005 gentoo vulnerability CVSS: 5.0 13 Jun 2006, 10:02 UTC

The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.

CVE-2006-1390 gentoo vulnerability CVSS: 4.6 25 Mar 2006, 00:06 UTC

The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.

CVE-2006-0071 gentoo vulnerability CVSS: 6.6 04 Jan 2006, 00:03 UTC

The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.

CVE-2005-3625 gentoo vulnerability CVSS: 10.0 31 Dec 2005, 05:00 UTC

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."

CVE-2005-4595 gentoo vulnerability CVSS: 7.2 31 Dec 2005, 05:00 UTC

Untrusted search path vulnerability (RPATH) in XnView 1.70 and NView 4.51 on Gentoo Linux allows local users to execute arbitrary code via a malicious library in the current working directory.

CVE-2005-3624 gentoo vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.

CVE-2005-3626 gentoo vulnerability CVSS: 5.0 31 Dec 2005, 05:00 UTC

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.

CVE-2005-4279 gentoo vulnerability CVSS: 7.2 16 Dec 2005, 11:03 UTC

Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

CVE-2005-3785 gentoo vulnerability CVSS: 5.0 23 Nov 2005, 23:03 UTC

Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the diff-eix program.

CVE-2005-2557 gentoo vulnerability CVSS: 4.3 28 Sep 2005, 21:03 UTC

Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.

CVE-2005-1267 gentoo vulnerability CVSS: 5.0 10 Jun 2005, 04:00 UTC

The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.

CVE-2005-1707 gentoo vulnerability CVSS: 4.6 24 May 2005, 04:00 UTC

The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.

CVE-2005-0002 gentoo vulnerability CVSS: 10.0 02 May 2005, 04:00 UTC

poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.

CVE-2005-0005 gentoo vulnerability CVSS: 7.5 02 May 2005, 04:00 UTC

Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.

CVE-2005-0427 gentoo vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.

CVE-2005-1121 gentoo vulnerability CVSS: 5.0 02 May 2005, 04:00 UTC

Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.

CVE-2005-0988 gentoo vulnerability CVSS: 3.7 02 May 2005, 04:00 UTC

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

CVE-2005-0077 gentoo vulnerability CVSS: 2.1 02 May 2005, 04:00 UTC

The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.

CVE-2005-0206 gentoo vulnerability CVSS: 7.5 27 Apr 2005, 04:00 UTC

The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.

CVE-2005-1270 gentoo vulnerability CVSS: 2.1 26 Apr 2005, 04:00 UTC

The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.

CVE-2005-0754 gentoo vulnerability CVSS: 7.5 22 Apr 2005, 04:00 UTC

Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.

CVE-2004-1004 gentoo vulnerability CVSS: 7.5 14 Apr 2005, 04:00 UTC

Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

CVE-2004-1005 gentoo vulnerability CVSS: 7.5 14 Apr 2005, 04:00 UTC

Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

CVE-2004-1175 gentoo vulnerability CVSS: 7.5 14 Apr 2005, 04:00 UTC

fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.

CVE-2004-1176 gentoo vulnerability CVSS: 7.5 14 Apr 2005, 04:00 UTC

Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVE-2004-1009 gentoo vulnerability CVSS: 5.0 14 Apr 2005, 04:00 UTC

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

CVE-2004-1090 gentoo vulnerability CVSS: 5.0 14 Apr 2005, 04:00 UTC

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."

CVE-2004-1091 gentoo vulnerability CVSS: 5.0 14 Apr 2005, 04:00 UTC

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.

CVE-2004-1092 gentoo vulnerability CVSS: 5.0 14 Apr 2005, 04:00 UTC

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.

CVE-2004-1093 gentoo vulnerability CVSS: 5.0 14 Apr 2005, 04:00 UTC

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."

CVE-2004-1174 gentoo vulnerability CVSS: 5.0 14 Apr 2005, 04:00 UTC

direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."

CVE-2005-0470 gentoo vulnerability CVSS: 5.0 14 Mar 2005, 05:00 UTC

Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.

CVE-2005-0667 gentoo vulnerability CVSS: 5.1 07 Mar 2005, 05:00 UTC

Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.

CVE-2004-0990 gentoo vulnerability CVSS: 10.0 01 Mar 2005, 05:00 UTC

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

CVE-2004-1034 gentoo vulnerability CVSS: 10.0 01 Mar 2005, 05:00 UTC

Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.

CVE-2004-1037 gentoo vulnerability CVSS: 10.0 01 Mar 2005, 05:00 UTC

The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.

CVE-2004-1052 gentoo vulnerability CVSS: 10.0 01 Mar 2005, 05:00 UTC

Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.

CVE-2004-1029 gentoo vulnerability CVSS: 9.3 01 Mar 2005, 05:00 UTC

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

CVE-2004-1031 gentoo vulnerability CVSS: 7.2 01 Mar 2005, 05:00 UTC

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as /proc/self/cmdline or /proc/self/environ.

CVE-2004-1036 gentoo vulnerability CVSS: 6.8 01 Mar 2005, 05:00 UTC

Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.

CVE-2004-1055 gentoo vulnerability CVSS: 6.8 01 Mar 2005, 05:00 UTC

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.

CVE-2004-0983 gentoo vulnerability CVSS: 5.0 01 Mar 2005, 05:00 UTC

The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.

CVE-2004-1027 gentoo vulnerability CVSS: 5.0 01 Mar 2005, 05:00 UTC

Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.

CVE-2004-1030 gentoo vulnerability CVSS: 2.1 01 Mar 2005, 05:00 UTC

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message.

CVE-2004-1032 gentoo vulnerability CVSS: 2.1 01 Mar 2005, 05:00 UTC

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.

CVE-2004-1033 gentoo vulnerability CVSS: 2.1 01 Mar 2005, 05:00 UTC

Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.

CVE-2005-0535 gentoo vulnerability CVSS: 7.5 22 Feb 2005, 05:00 UTC

Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.

CVE-2004-0947 gentoo vulnerability CVSS: 10.0 09 Feb 2005, 05:00 UTC

Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.

CVE-2004-0980 gentoo vulnerability CVSS: 10.0 09 Feb 2005, 05:00 UTC

Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.

CVE-2004-0981 gentoo vulnerability CVSS: 10.0 09 Feb 2005, 05:00 UTC

Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.

CVE-2004-0937 gentoo vulnerability CVSS: 7.5 09 Feb 2005, 05:00 UTC

Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

CVE-2004-0969 gentoo vulnerability CVSS: 2.1 09 Feb 2005, 05:00 UTC

The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

CVE-2004-0972 gentoo vulnerability CVSS: 2.1 09 Feb 2005, 05:00 UTC

The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

CVE-2004-0975 gentoo vulnerability CVSS: 2.1 09 Feb 2005, 05:00 UTC

The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.

CVE-2004-0888 gentoo vulnerability CVSS: 10.0 27 Jan 2005, 05:00 UTC

Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.

CVE-2004-0889 gentoo vulnerability CVSS: 10.0 27 Jan 2005, 05:00 UTC

Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.

CVE-2004-0891 gentoo vulnerability CVSS: 10.0 27 Jan 2005, 05:00 UTC

Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.

CVE-2004-0932 gentoo vulnerability CVSS: 7.5 27 Jan 2005, 05:00 UTC

McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

CVE-2004-0933 gentoo vulnerability CVSS: 7.5 27 Jan 2005, 05:00 UTC

Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

CVE-2004-0934 gentoo vulnerability CVSS: 7.5 27 Jan 2005, 05:00 UTC

Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

CVE-2004-0935 gentoo vulnerability CVSS: 7.5 27 Jan 2005, 05:00 UTC

Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

CVE-2004-0936 gentoo vulnerability CVSS: 7.5 27 Jan 2005, 05:00 UTC

RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

CVE-2004-0918 gentoo vulnerability CVSS: 5.0 27 Jan 2005, 05:00 UTC

The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.

CVE-2004-0930 gentoo vulnerability CVSS: 5.0 27 Jan 2005, 05:00 UTC

The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.

CVE-2004-0881 gentoo vulnerability CVSS: 2.1 27 Jan 2005, 05:00 UTC

getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.

CVE-2004-0880 gentoo vulnerability CVSS: 1.2 27 Jan 2005, 05:00 UTC

getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.

CVE-2004-0914 gentoo vulnerability CVSS: 10.0 10 Jan 2005, 05:00 UTC

Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.

CVE-2004-1025 gentoo vulnerability CVSS: 10.0 10 Jan 2005, 05:00 UTC

Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.

CVE-2004-1026 gentoo vulnerability CVSS: 10.0 10 Jan 2005, 05:00 UTC

Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.

CVE-2004-1304 gentoo vulnerability CVSS: 10.0 10 Jan 2005, 05:00 UTC

Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.

CVE-2004-1096 gentoo vulnerability CVSS: 7.5 10 Jan 2005, 05:00 UTC

Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

CVE-2004-1161 gentoo vulnerability CVSS: 7.5 10 Jan 2005, 05:00 UTC

rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.

CVE-2004-1162 gentoo vulnerability CVSS: 7.5 10 Jan 2005, 05:00 UTC

The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.

CVE-2004-1115 gentoo vulnerability CVSS: 7.2 10 Jan 2005, 05:00 UTC

The init scripts in Search for Extraterrestrial Intelligence (SETI) project 3.08-r3 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.

CVE-2004-1116 gentoo vulnerability CVSS: 7.2 10 Jan 2005, 05:00 UTC

The init scripts in Great Internet Mersenne Prime Search (GIMPS) 23.9 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.

CVE-2004-1117 gentoo vulnerability CVSS: 7.2 10 Jan 2005, 05:00 UTC

The init scripts in ChessBrain 20407 and earlier execute user-owned programs with root privileges, which allows local users to gain privileges by modifying the programs.

CVE-2004-1106 gentoo vulnerability CVSS: 6.8 10 Jan 2005, 05:00 UTC

Cross-site scripting (XSS) vulnerability in Gallery 1.4.4-pl3 and earlier allows remote attackers to execute arbitrary web script or HTML via "specially formed URLs," possibly via the include parameter in index.php.

CVE-2004-1167 gentoo vulnerability CVSS: 5.0 10 Jan 2005, 05:00 UTC

mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite arbitrary files via a symlink attack.

CVE-2004-0996 gentoo vulnerability CVSS: 2.1 10 Jan 2005, 05:00 UTC

main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.

CVE-2004-1107 gentoo vulnerability CVSS: 2.1 10 Jan 2005, 05:00 UTC

dispatch-conf in Portage 2.0.51-r2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVE-2004-1108 gentoo vulnerability CVSS: 2.1 10 Jan 2005, 05:00 UTC

qpkg in Gentoolkit 0.2.0_pre10 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary directory.

CVE-2004-1110 gentoo vulnerability CVSS: 2.1 10 Jan 2005, 05:00 UTC

The mtink status monitor before 1.0.5 for Epson printers allows local users to overwrite arbitrary files via a symlink attack on the epson temporary file.

CVE-2004-1452 gentoo vulnerability CVSS: 7.2 31 Dec 2004, 05:00 UTC

Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.

CVE-2004-1471 gentoo vulnerability CVSS: 7.1 31 Dec 2004, 05:00 UTC

Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.

CVE-2004-1491 gentoo vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

CVE-2004-1901 gentoo vulnerability CVSS: 4.6 31 Dec 2004, 05:00 UTC

Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.

CVE-2004-0834 gentoo vulnerability CVSS: 7.2 23 Dec 2004, 05:00 UTC

Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.

CVE-2004-0749 gentoo vulnerability CVSS: 5.0 23 Dec 2004, 05:00 UTC

The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.

CVE-2004-1336 gentoo vulnerability CVSS: 2.1 23 Dec 2004, 05:00 UTC

The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.

CVE-2004-1307 gentoo vulnerability CVSS: 7.5 21 Dec 2004, 05:00 UTC

Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.

CVE-2004-0608 gentoo vulnerability CVSS: 10.0 06 Dec 2004, 05:00 UTC

The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.

CVE-2004-0456 gentoo vulnerability CVSS: 7.6 06 Dec 2004, 05:00 UTC

Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.

CVE-2004-0496 gentoo vulnerability CVSS: 7.2 06 Dec 2004, 05:00 UTC

Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.

CVE-2004-0604 gentoo vulnerability CVSS: 5.0 06 Dec 2004, 05:00 UTC

The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.

CVE-2004-0626 gentoo vulnerability CVSS: 5.0 06 Dec 2004, 05:00 UTC

The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type.

CVE-2004-0633 gentoo vulnerability CVSS: 5.0 06 Dec 2004, 05:00 UTC

The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.

CVE-2004-0634 gentoo vulnerability CVSS: 5.0 06 Dec 2004, 05:00 UTC

The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.

CVE-2004-0635 gentoo vulnerability CVSS: 5.0 06 Dec 2004, 05:00 UTC

The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.

CVE-2004-0497 gentoo vulnerability CVSS: 2.1 06 Dec 2004, 05:00 UTC

Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.

CVE-2004-0565 gentoo vulnerability CVSS: 2.1 06 Dec 2004, 05:00 UTC

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

CVE-2004-0333 gentoo vulnerability CVSS: 10.0 23 Nov 2004, 05:00 UTC

Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.

CVE-2004-0746 gentoo vulnerability CVSS: 7.5 20 Oct 2004, 04:00 UTC

Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

CVE-2004-0500 gentoo vulnerability CVSS: 7.5 28 Sep 2004, 04:00 UTC

Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.

CVE-2004-0809 gentoo vulnerability CVSS: 5.0 16 Sep 2004, 04:00 UTC

The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.

CVE-2004-0226 gentoo vulnerability CVSS: 10.0 18 Aug 2004, 04:00 UTC

Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

CVE-2004-0419 gentoo vulnerability CVSS: 7.5 18 Aug 2004, 04:00 UTC

XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.

CVE-2004-0432 gentoo vulnerability CVSS: 7.5 18 Aug 2004, 04:00 UTC

ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.

CVE-2004-0232 gentoo vulnerability CVSS: 5.0 18 Aug 2004, 04:00 UTC

Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.

CVE-2004-0229 gentoo vulnerability CVSS: 4.6 18 Aug 2004, 04:00 UTC

The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.

CVE-2004-0231 gentoo vulnerability CVSS: 2.1 18 Aug 2004, 04:00 UTC

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

CVE-2004-1737 gentoo vulnerability CVSS: 7.5 16 Aug 2004, 04:00 UTC

SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.

CVE-2004-0414 gentoo vulnerability CVSS: 10.0 06 Aug 2004, 04:00 UTC

CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.

CVE-2004-0416 gentoo vulnerability CVSS: 10.0 06 Aug 2004, 04:00 UTC

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

CVE-2004-0418 gentoo vulnerability CVSS: 10.0 06 Aug 2004, 04:00 UTC

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

CVE-2004-0557 gentoo vulnerability CVSS: 10.0 06 Aug 2004, 04:00 UTC

Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

CVE-2004-0649 gentoo vulnerability CVSS: 10.0 06 Aug 2004, 04:00 UTC

Buffer overflow in write_packet in control.c for l2tpd may allow remote attackers to execute arbitrary code.

CVE-2004-0495 gentoo vulnerability CVSS: 7.2 06 Aug 2004, 04:00 UTC

Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.

CVE-2004-0548 gentoo vulnerability CVSS: 7.2 06 Aug 2004, 04:00 UTC

Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.

CVE-2004-0667 gentoo vulnerability CVSS: 7.2 06 Aug 2004, 04:00 UTC

Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to sys_creat, sys_open, and sys_mknod inside jails, which could allow local users to gain elevated privileges.

CVE-2004-0493 gentoo vulnerability CVSS: 6.4 06 Aug 2004, 04:00 UTC

The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.

CVE-2004-0417 gentoo vulnerability CVSS: 5.0 06 Aug 2004, 04:00 UTC

Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.

CVE-2004-0535 gentoo vulnerability CVSS: 2.1 06 Aug 2004, 04:00 UTC

The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.

CVE-2004-0554 gentoo vulnerability CVSS: 2.1 06 Aug 2004, 04:00 UTC

Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

CVE-2004-0700 gentoo vulnerability CVSS: 7.5 27 Jul 2004, 04:00 UTC

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow remote attackers to execute arbitrary messages via format string specifiers in certain log messages for HTTPS that are handled by the ssl_log function.

CVE-2004-0386 gentoo vulnerability CVSS: 10.0 04 May 2004, 04:00 UTC

Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.

CVE-2004-1983 gentoo vulnerability CVSS: 2.1 02 May 2004, 04:00 UTC

The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.

CVE-2004-0224 gentoo vulnerability CVSS: 7.5 15 Apr 2004, 04:00 UTC

Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute arbitrary code "when Unicode character is out of BMP range."

CVE-2003-1422 gentoo vulnerability CVSS: 10.0 31 Dec 2003, 05:00 UTC

Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.

CVE-2003-0694 gentoo vulnerability CVSS: 10.0 06 Oct 2003, 04:00 UTC

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

CVE-2003-0681 gentoo vulnerability CVSS: 7.5 06 Oct 2003, 04:00 UTC

A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.

CVE-2002-1337 gentoo vulnerability CVSS: 10.0 07 Mar 2003, 05:00 UTC

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.