Vulnerability index

Browse CVEs

102 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-36770 pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem… Ebuild For Slurm after 22.05.3 Fix from $2,3002024-01-15 CRITICAL 9.8 CVE-2016-20021 In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does n… Portage 3.0.47+ Fix from $2,3002024-01-12 CRITICAL 9.8 CVE-2023-28424 Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in … Soko 1.0.2+ Fix from $2,3002023-03-20 CRITICAL 9.1 CVE-2023-26033 Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injection, leading to a Denial of Service. If … Soko 1.0.1+ Fix from $2,3002023-02-25 MEDIUM 5.5 CVE-2019-20384 Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to th… Portage after 2.3.84 Fix from $1,6002020-01-21 HIGH 7.3 CVE-2017-14484 The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by cr… Sci Mathematics Gimps Patch available Fix from $1,9502017-09-15 MEDIUM 5.5 CVE-2017-14483 flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-root account, which might all… Dev Python Flower after 0.9.1 Fix from $1,6002017-09-15 HIGH 7.1 CVE-2004-2778 Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to… Portage Mitigation only Fix from $1,9502017-06-27 MEDIUM 6.8 CVE-2014-9622 Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execu… Xdg Utils No fix yet Fix from $1,6002015-01-21 HIGH 9.3 CVE-2013-2100 The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers,… Portage Patch available Fix from $1,9502014-09-29 MEDIUM 5.0 CVE-2013-4223 The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP aut… Nullmailer Mitigation only Fix from $1,6002014-05-23 MEDIUM 6.8 CVE-2010-1159EPSS 7% Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code… Linux after 1.0 Fix from $1,6002013-10-28 MEDIUM 6.8 CVE-2012-4893 Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authenti… Webmin after 1.590 Fix from $1,6002012-09-11 MEDIUM 6.5 CVE-2012-2982EPSS 62% file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as … Webmin after 1.590 Fix from $1,6002012-09-11 MEDIUM 6.0 CVE-2012-2981 Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor ty… Webmin after 1.590 Fix from $1,6002012-09-11 MEDIUM 5.0 CVE-2012-2983EPSS 20% file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote… Webmin after 1.590 Fix from $1,6002012-09-11 MEDIUM 6.9 CVE-2011-1154 The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell… Logrotate after 3.7.9 Fix from $1,6002011-03-30 MEDIUM 6.3 CVE-2011-1548 The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, wh… Logrotate Mitigation only Fix from $1,6002011-03-30 MEDIUM 6.3 CVE-2011-1549 The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which … Logrotate Mitigation only Fix from $1,6002011-03-30 MEDIUM 6.3 CVE-2011-1550 The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write acces… Logrotate Mitigation only Fix from $1,6002011-03-30 HIGH 7.2 CVE-2008-4580 fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fi… Cman Mitigation only Fix from $1,9502008-10-15 MEDIUM 6.9 CVE-2008-4394 Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allow… Portage after 2.1.4.4 Fix from $1,6002008-10-10 HIGH 7.2 CVE-2008-1078 expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a syml… Linux No fix yet Fix from $1,9502008-02-29 MEDIUM 6.8 CVE-2008-0386 Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg… Xdg Utils after 1.0.2 Fix from $1,6002008-02-04 MEDIUM 6.8 CVE-2007-5714 The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote a… Mldonkey Ebuild after 2.9.0 Fix from $1,6002007-10-30 MEDIUM 6.6 CVE-2007-3531 The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink att… Nvclock after 0.7 Fix from $1,6002007-07-25 HIGH 7.2 CVE-2007-3508 Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large … Glibc after 2.5 Fix from $1,9502007-07-03 HIGH 10.0 CVE-2007-2194EPSS 19% Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long secti… Xnview No fix yet Fix from $1,9502007-04-24 MEDIUM 5.0 CVE-2006-3005 The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers … Linux Patch available Fix from $1,6002006-06-13 MEDIUM 6.6 CVE-2006-0071 The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitra… Linux Patch available Fix from $1,6002006-01-04