Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Radius HIGH 10.0
CVE-2006-4181

Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execut…

Patch available
Fix from $1,950 2006-11-28
Gv MEDIUM 5.1
CVE-2006-5864EPSS 15%

Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to exe…

No fix yet
Fix from $1,600 2006-11-11
Mailman HIGH 7.5
CVE-2006-2191

Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed…

Fix: after 2.1.8
Fix from $1,950 2006-09-19
Gnutls MEDIUM 5.0
CVE-2006-4790

verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field …

Patch available
Fix from $1,600 2006-09-14
Mailman MEDIUM 6.8
CVE-2006-3636EPSS 7%

Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unsp…

Patch available
Fix from $1,600 2006-09-06
Mailman MEDIUM 5.0
CVE-2006-2941

Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted…

Patch available
Fix from $1,600 2006-09-06
Gdb MEDIUM 5.1
CVE-2006-4146

Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers,…

Patch available
Fix from $1,600 2006-08-31
Binutils HIGH 7.3
CVE-2006-2362EPSS 14%

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-depe…

Fix: 2.17+
Fix from $1,950 2006-05-15
Mailman MEDIUM 5.0
CVE-2006-0052

The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a …

Patch available
Fix from $1,600 2006-03-31
Privacy Guard MEDIUM 5.0
CVE-2006-0049

gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that i…

Patch available
Fix from $1,600 2006-03-13
Tar MEDIUM 5.1
CVE-2006-0300EPSS 5%

Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code…

Patch available
Fix from $1,600 2006-02-24
Phpbook HIGH 7.5
CVE-2006-0075

Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (m…

Fix: after 1.3.2
Fix from $1,950 2006-01-04
Mailman HIGH 7.8
CVE-2005-4153

Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on ba…

Patch available
Fix from $1,950 2005-12-11
Gnump3d MEDIUM 6.4
CVE-2005-3355

Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values".

Patch available
Fix from $1,600 2005-11-18
Mailman MEDIUM 5.0
CVE-2005-3573

Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to…

Mitigation only
Fix from $1,600 2005-11-16
Gnump3d MEDIUM 5.0
CVE-2005-3123

Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////…

Patch available
Fix from $1,600 2005-10-30
Mailutils HIGH 7.5
CVE-2005-2878EPSS 15%

Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via for…

Patch available
Fix from $1,950 2005-09-13
Tar HIGH 10.0
CVE-2005-2541

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.

Mitigation only
Fix from $1,950 2005-08-10
Mailutils HIGH 7.5
CVE-2005-1824

The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which…

Patch available
Fix from $1,950 2005-06-02
Mailutils HIGH 7.5
CVE-2005-1520EPSS 7%

Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote atta…

Patch available
Fix from $1,950 2005-05-26
Mailutils HIGH 7.5
CVE-2005-1521

Integer overflow in the fetch_io function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attacker…

Patch available
Fix from $1,950 2005-05-26
Mailutils HIGH 7.5
CVE-2005-1523EPSS 10%

Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbit…

Patch available
Fix from $1,950 2005-05-26
Mailutils MEDIUM 5.0
CVE-2005-1522

The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CP…

Patch available
Fix from $1,600 2005-05-26
Gdb HIGH 7.2
CVE-2005-1705

gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands…

Fix: after 6.3
Fix from $1,950 2005-05-24
Gnutls MEDIUM 5.0
CVE-2005-1431

The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related t…

Mitigation only
Fix from $1,600 2005-05-03
Mailman MEDIUM 5.0
CVE-2005-0202

Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary fil…

Patch available
Fix from $1,600 2005-05-02
Gzip MEDIUM 5.0
CVE-2005-1228

Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot do…

Patch available
Fix from $1,600 2005-05-02
Wget MEDIUM 5.0
CVE-2004-1487

wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP …

No fix yet
Fix from $1,600 2005-04-27
Wget MEDIUM 5.0
CVE-2004-1488EPSS 12%

wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web…

No fix yet
Fix from $1,600 2005-04-27
Emacs HIGH 7.5
CVE-2005-0100

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows rem…

Fix: after 21.4
Fix from $1,950 2005-02-07