Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cfengine HIGH 7.5
CVE-2003-0849EPSS 11%

Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length val…

Mitigation only
Fix from $1,950 2003-11-17
Fileutils MEDIUM 5.0
CVE-2003-0853EPSS 10%

An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a l…

Patch available
Fix from $1,600 2003-11-17
Lsh HIGH 7.5
CVE-2003-0826EPSS 12%

lsh daemon (lshd) does not properly return from certain functions in (1) read_line.c, (2) channel_commands.c, or (3) client_keyexchange.c when long i…

Mitigation only
Fix from $1,950 2003-10-06
Privacy Guard HIGH 10.0
CVE-2003-0255EPSS 7%

The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validi…

Fix: after 1.2.1
Fix from $1,950 2003-05-27
Data Display Debugger HIGH 7.2
CVE-2002-2099

Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME…

No fix yet
Fix from $1,950 2002-12-31
Wget MEDIUM 5.0
CVE-2002-1344

Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames conta…

Patch available
Fix from $1,600 2002-12-18
Glibc MEDIUM 5.0
CVE-2002-1265

The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows…

Mitigation only
Fix from $1,600 2002-11-12
Tar MEDIUM 5.0
CVE-2002-1216

GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modif…

Fix: after 1.13.25
Fix from $1,600 2002-10-28
Glibc MEDIUM 5.0
CVE-2002-1146

The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer s…

Fix: after 2.2.5
Fix from $1,600 2002-10-11
Tar MEDIUM 5.0
CVE-2002-0399

Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files duri…

Mitigation only
Fix from $1,600 2002-10-10
Mailman HIGH 7.5
CVE-2002-0855EPSS 6%

Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via a subscriber's list subscrip…

Patch available
Fix from $1,950 2002-09-05
Glibc HIGH 7.5
CVE-2002-0684EPSS 6%

Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and ear…

Fix: after 2.2.5
Fix from $1,950 2002-08-12
Mailman HIGH 7.5
CVE-2002-0388EPSS 6%

Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Piper…

Fix: after 2.0.11
Fix from $1,950 2002-06-18
Sharutils HIGH 7.2
CVE-2002-0178

uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, w…

Patch available
Fix from $1,950 2002-05-29
Chess HIGH 7.5
CVE-2002-0204

Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user app…

Fix: after 5.02
Fix from $1,950 2002-05-16
Groff HIGH 7.5
CVE-2002-0003

Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system.

Fix: after 1.16
Fix from $1,950 2002-02-27
Mailman MEDIUM 5.1
CVE-2001-0884

Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentia…

Patch available
Fix from $1,600 2001-12-21
Gzip HIGH 7.5
CVE-2001-1228

Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run…

Patch available
Fix from $1,950 2001-11-18
Mailman HIGH 7.5
CVE-2001-1132

Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is…

Fix: after 2.0.5
Fix from $1,950 2001-09-05
Findutils HIGH 7.2
CVE-2001-1036

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that con…

No fix yet
Fix from $1,950 2001-08-31
Privacy Guard HIGH 7.5
CVE-2001-0522EPSS 14%

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in t…

Patch available
Fix from $1,950 2001-08-14
Groff HIGH 7.5
CVE-2001-1022EPSS 11%

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S optio…

Patch available
Fix from $1,950 2001-07-26
Privacy Guard MEDIUM 5.0
CVE-2001-0072

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private ke…

Patch available
Fix from $1,600 2001-02-12
Groff HIGH 10.0
CVE-2000-0803

GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including …

Fix: 1.17+
Fix from $1,950 2000-12-19
Cfengine HIGH 10.0
CVE-2000-0947

Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the…

Patch available
Fix from $1,950 2000-12-19
Privacy Guard HIGH 7.5
CVE-2000-0974

GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all …

Patch available
Fix from $1,950 2000-12-19
Glibc HIGH 7.2
CVE-2000-0824

The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could al…

Patch available
Fix from $1,950 2000-11-14
Mailman HIGH 7.2
CVE-2000-0861

Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.

Patch available
Fix from $1,950 2000-11-14
G\+\+ HIGH 7.5
CVE-2000-1219

The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable …

Fix: after 3.3.3
Fix from $1,950 2000-11-01
Glibc HIGH 7.5
CVE-2000-0335

The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.

Mitigation only
Fix from $1,950 2000-05-03