Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gnutls HIGH 7.5
CVE-2009-1416

lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might…

Patch available
Fix from $1,950 2009-04-30
Gnutls MEDIUM 5.0
CVE-2009-1417

gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to success…

Fix: after 2.6.5
Fix from $1,600 2009-04-30
Escript MEDIUM 6.8
CVE-2008-5078

Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and p…

Mitigation only
Fix from $1,600 2008-12-19
Classpath HIGH 7.5
CVE-2008-5659

The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for…

Fix: after 0.97.2
Fix from $1,950 2008-12-17
Enscript HIGH 7.6
CVE-2008-3863EPSS 8%

Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes…

Mitigation only
Fix from $1,950 2008-10-23
Ibackup HIGH 7.2
CVE-2008-4475

ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Mitigation only
Fix from $1,950 2008-10-07
Adns MEDIUM 6.4
CVE-2008-4100

GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoo…

Fix: after 1.4
Fix from $1,600 2008-09-18
Ed HIGH 9.3
CVE-2008-3916

Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to exec…

Mitigation only
Fix from $1,950 2008-09-04
Gnutls HIGH 7.6
CVE-2008-2377EPSS 5%

Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.…

Patch available
Fix from $1,950 2008-08-08
Gnutls HIGH 10.0
CVE-2008-1948EPSS 12%

The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate …

Patch available
Fix from $1,950 2008-05-21
Gnutls HIGH 9.3
CVE-2008-1949EPSS 6%

The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello m…

Patch available
Fix from $1,950 2008-05-21
Gnutls MEDIUM 5.0
CVE-2008-1950

Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attac…

Patch available
Fix from $1,600 2008-05-21
Emacs MEDIUM 6.8
CVE-2008-2142

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which al…

No fix yet
Fix from $1,600 2008-05-12
M4 HIGH 7.5
CVE-2008-1687

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow contex…

Fix: after 1.4.10
Fix from $1,950 2008-04-09
M4 HIGH 7.5
CVE-2008-1688

Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of …

Patch available
Fix from $1,950 2008-04-09
Gcc MEDIUM 6.8
CVE-2008-1685

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to…

Mitigation only
Fix from $1,600 2008-04-06
Gcc HIGH 7.5
CVE-2008-1367

gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, whic…

No fix yet
Fix from $1,950 2008-03-17
Libcdio MEDIUM 5.0
CVE-2007-6613EPSS 13%

Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio…

Fix: after 0.79
Fix from $1,600 2008-01-03
Emacs HIGH 10.0
CVE-2007-6109

Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified ot…

Mitigation only
Fix from $1,950 2007-12-07
Gnump3d MEDIUM 5.0
CVE-2007-6130

gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attackers to bypass intended access restrictions.

Mitigation only
Fix from $1,600 2007-11-26
Emacs MEDIUM 6.3
CVE-2007-5795

The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risk…

Fix: after 22.1
Fix from $1,600 2007-11-02
Tramp MEDIUM 6.9
CVE-2007-5377

The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, a…

Mitigation only
Fix from $1,600 2007-10-12
Tar MEDIUM 6.8
CVE-2007-4131

Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbit…

Patch available
Fix from $1,600 2007-08-25
Screen HIGH 7.2
CVE-2007-3048

GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability…

Mitigation only
Fix from $1,950 2007-06-05
Findutils MEDIUM 6.0
CVE-2007-2452

Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent…

Patch available
Fix from $1,600 2007-06-04
Flash Player HIGH 10.0
CVE-2007-2500EPSS 5%

server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of…

Fix: after 0.7.2
Fix from $1,950 2007-05-04
Libtool Ltdl MEDIUM 6.6
CVE-2006-7151

Untrusted search path vulnerability in the libtool-ltdl library (libltdl.so) 1.5.22-2.3 in Fedora Core 5 might allow local users to execute arbitrary…

Mitigation only
Fix from $1,600 2007-03-07
Gpgme MEDIUM 5.0
CVE-2007-1263EPSS 5%

GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP…

Fix: after 1.4.6
Fix from $1,600 2007-03-06
Gnumail MEDIUM 5.0
CVE-2007-1269

GNUMail 1.1.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents GNUMail from visually distinguishing bet…

Fix: after 1.1.2
Fix from $1,600 2007-03-06
Wget MEDIUM 5.0
CVE-2006-6719

The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (applicat…

No fix yet
Fix from $1,600 2006-12-23