Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enscript HIGH 7.5
CVE-2004-1185

Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.

Patch available
Fix from $1,950 2005-01-21
A2ps HIGH 10.0
CVE-2004-1170EPSS 16%

a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

Patch available
Fix from $1,950 2005-01-10
Gnutls HIGH 7.8
CVE-2004-2531

X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service…

Patch available
Fix from $1,950 2004-12-31
Queue HIGH 7.5
CVE-2004-0555

Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.

Patch available
Fix from $1,950 2004-12-31
Mailman HIGH 7.5
CVE-2004-1143

The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwo…

Patch available
Fix from $1,950 2004-12-31
Sharutils HIGH 7.5
CVE-2004-1773

Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) un…

Patch available
Fix from $1,950 2004-12-31
Gnubiff HIGH 7.5
CVE-2004-2461

Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code.

Patch available
Fix from $1,950 2004-12-31
Mailutils HIGH 7.2
CVE-2004-0984

Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.

Fix: after 1.0.5.4
Fix from $1,950 2004-12-31
Less MEDIUM 6.4
CVE-2004-2264

Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or p…

Mitigation only
Fix from $1,600 2004-12-31
Enscript MEDIUM 5.0
CVE-2004-1186

Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).

Patch available
Fix from $1,600 2004-12-31
Gnubiff MEDIUM 5.0
CVE-2004-2460

Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Uniq…

Patch available
Fix from $1,600 2004-12-31
Radius MEDIUM 5.0
CVE-2004-0849

Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --…

Patch available
Fix from $1,600 2004-12-23
Gzip HIGH 10.0
CVE-2004-0603

gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow rem…

Fix: after 1.3.3
Fix from $1,950 2004-12-06
Gnats HIGH 10.0
CVE-2004-0623

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string…

Patch available
Fix from $1,950 2004-12-06
Radius MEDIUM 5.0
CVE-2004-0576

The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (ser…

Patch available
Fix from $1,600 2004-12-06
Anubis HIGH 10.0
CVE-2004-0353

Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain pri…

Patch available
Fix from $1,950 2004-11-23
Anubis HIGH 10.0
CVE-2004-0354EPSS 16%

Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via form…

Patch available
Fix from $1,950 2004-11-23
Cvs MEDIUM 5.0
CVE-2004-0778

CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X…

Fix: 1.11.17 / 1.12.9+
Fix from $1,600 2004-10-20
Mailman MEDIUM 5.0
CVE-2004-0412

Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.

Patch available
Fix from $1,600 2004-08-18
Cfengine HIGH 10.0
CVE-2004-1701EPSS 20%

Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitra…

Patch available
Fix from $1,950 2004-08-09
Cfengine MEDIUM 5.0
CVE-2004-1702

The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction funct…

Patch available
Fix from $1,600 2004-08-09
Mailman MEDIUM 5.0
CVE-2004-0182

Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.

Fix: after 2.0.12
Fix from $1,600 2004-06-01
Mailman MEDIUM 5.0
CVE-2003-0991

Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed…

Patch available
Fix from $1,600 2004-03-03
Radius MEDIUM 5.0
CVE-2004-0131

The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) vi…

Patch available
Fix from $1,600 2004-03-03
Mailman MEDIUM 6.8
CVE-2003-0965

Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduc…

Fix: after 2.1.4
Fix from $1,600 2004-02-17
Privacy Guard HIGH 7.5
CVE-2003-0978

Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows r…

Mitigation only
Fix from $1,950 2004-01-05
Emacs MEDIUM 5.1
CVE-2003-1232

Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted at…

Patch available
Fix from $1,600 2003-12-31
Screen HIGH 10.0
CVE-2003-0972

Integer signedness error in ansi.c for GNU screen 4.0.1 and earlier, and 3.9.15 and earlier, allows local users to execute arbitrary code via a large…

Patch available
Fix from $1,950 2003-12-15
Zebra MEDIUM 5.0
CVE-2003-0795EPSS 8%

The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marke…

Fix: after 0.96.3
Fix from $1,600 2003-12-15
Privacy Guard MEDIUM 5.0
CVE-2003-0971

GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for sig…

Patch available
Fix from $1,600 2003-12-15