Vulnerability index

Browse CVEs

188 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

A2ps MEDIUM 6.8
CVE-2014-0466

The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files o…

Mitigation only
Fix from $1,600 2014-04-03
Cpio HIGH 7.2
CVE-2010-4226

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within…

Mitigation only
Fix from $1,950 2014-02-06
Gnutls MEDIUM 5.0
CVE-2013-2116

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over…

Mitigation only
Fix from $1,600 2013-07-03
Glibc MEDIUM 6.8
CVE-2012-0864

Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass th…

No fix yet
Fix from $1,600 2013-05-02
Gnash MEDIUM 6.8
CVE-2012-1175

Integer overflow in the GnashImage::size method in libbase/GnashImage.h in GNU Gnash 0.8.10 allows remote attackers to cause a denial of service (cra…

Mitigation only
Fix from $1,600 2012-08-26
Phpbook MEDIUM 5.0
CVE-2011-3771

phpBook 2.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …

Mitigation only
Fix from $1,600 2011-09-24
Glibc HIGH 7.5
CVE-2010-0015

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.bynam…

Mitigation only
Fix from $1,950 2010-01-14
Escript MEDIUM 6.8
CVE-2008-5078

Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and p…

Mitigation only
Fix from $1,600 2008-12-19
Enscript HIGH 7.6
CVE-2008-3863EPSS 8%

Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes…

Mitigation only
Fix from $1,950 2008-10-23
Ibackup HIGH 7.2
CVE-2008-4475

ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Mitigation only
Fix from $1,950 2008-10-07
Ed HIGH 9.3
CVE-2008-3916

Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to exec…

Mitigation only
Fix from $1,950 2008-09-04
Emacs MEDIUM 6.8
CVE-2008-2142

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which al…

No fix yet
Fix from $1,600 2008-05-12
Gcc MEDIUM 6.8
CVE-2008-1685

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to…

Mitigation only
Fix from $1,600 2008-04-06
Gcc HIGH 7.5
CVE-2008-1367

gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, whic…

No fix yet
Fix from $1,950 2008-03-17
Emacs HIGH 10.0
CVE-2007-6109

Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified ot…

Mitigation only
Fix from $1,950 2007-12-07
Gnump3d MEDIUM 5.0
CVE-2007-6130

gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attackers to bypass intended access restrictions.

Mitigation only
Fix from $1,600 2007-11-26
Tramp MEDIUM 6.9
CVE-2007-5377

The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, a…

Mitigation only
Fix from $1,600 2007-10-12
Screen HIGH 7.2
CVE-2007-3048

GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability…

Mitigation only
Fix from $1,950 2007-06-05
Libtool Ltdl MEDIUM 6.6
CVE-2006-7151

Untrusted search path vulnerability in the libtool-ltdl library (libltdl.so) 1.5.22-2.3 in Fedora Core 5 might allow local users to execute arbitrary…

Mitigation only
Fix from $1,600 2007-03-07
Wget MEDIUM 5.0
CVE-2006-6719

The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (applicat…

No fix yet
Fix from $1,600 2006-12-23
Gv MEDIUM 5.1
CVE-2006-5864EPSS 15%

Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to exe…

No fix yet
Fix from $1,600 2006-11-11
Mailman MEDIUM 5.0
CVE-2005-3573

Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to…

Mitigation only
Fix from $1,600 2005-11-16
Tar HIGH 10.0
CVE-2005-2541

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.

Mitigation only
Fix from $1,950 2005-08-10
Gnutls MEDIUM 5.0
CVE-2005-1431

The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related t…

Mitigation only
Fix from $1,600 2005-05-03
Wget MEDIUM 5.0
CVE-2004-1487

wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP …

No fix yet
Fix from $1,600 2005-04-27
Wget MEDIUM 5.0
CVE-2004-1488EPSS 12%

wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web…

No fix yet
Fix from $1,600 2005-04-27
Less MEDIUM 6.4
CVE-2004-2264

Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or p…

Mitigation only
Fix from $1,600 2004-12-31
Privacy Guard HIGH 7.5
CVE-2003-0978

Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows r…

Mitigation only
Fix from $1,950 2004-01-05
Cfengine HIGH 7.5
CVE-2003-0849EPSS 11%

Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length val…

Mitigation only
Fix from $1,950 2003-11-17
Lsh HIGH 7.5
CVE-2003-0826EPSS 12%

lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long i…

Mitigation only
Fix from $1,950 2003-10-06