Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2009-1416
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might…
Gnutls
Patch available
MEDIUM 5.0
CVE-2009-1417
gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to success…
Gnutls
after 2.6.5
MEDIUM 6.8
CVE-2008-5078
Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and p…
Escript
Mitigation only
HIGH 7.5
CVE-2008-5659
The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for…
Classpath
after 0.97.2
HIGH 7.6
CVE-2008-3863EPSS 8%
Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes…
Enscript
Mitigation only
HIGH 7.2
CVE-2008-4475
ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Ibackup
Mitigation only
MEDIUM 6.4
CVE-2008-4100
GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoo…
Adns
after 1.4
HIGH 9.3
CVE-2008-3916
Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to exec…
Ed
Mitigation only
HIGH 7.6
CVE-2008-2377EPSS 5%
Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.…
Gnutls
Patch available
HIGH 10.0
CVE-2008-1948EPSS 12%
The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate …
Gnutls
Patch available
HIGH 9.3
CVE-2008-1949EPSS 6%
The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello m…
Gnutls
Patch available
MEDIUM 5.0
CVE-2008-1950
Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attac…
Gnutls
Patch available
MEDIUM 6.8
CVE-2008-2142
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which al…
Emacs
No fix yet
HIGH 7.5
CVE-2008-1687
The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow contex…
M4
after 1.4.10
HIGH 7.5
CVE-2008-1688
Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of …
M4
Patch available
MEDIUM 6.8
CVE-2008-1685
gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to…
Gcc
Mitigation only
HIGH 7.5
CVE-2008-1367
gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, whic…
Gcc
No fix yet
MEDIUM 5.0
CVE-2007-6613EPSS 13%
Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio…
Libcdio
after 0.79
HIGH 10.0
CVE-2007-6109
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified ot…
Emacs
Mitigation only
MEDIUM 5.0
CVE-2007-6130
gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attackers to bypass intended access restrictions.
Gnump3d
Mitigation only
MEDIUM 6.3
CVE-2007-5795
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risk…
Emacs
after 22.1
MEDIUM 6.9
CVE-2007-5377
The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, a…
Tramp
Mitigation only
MEDIUM 6.8
CVE-2007-4131
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbit…
Tar
Patch available
HIGH 7.2
CVE-2007-3048
GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability…
Screen
Mitigation only
MEDIUM 6.0
CVE-2007-2452
Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent…
Findutils
Patch available
HIGH 10.0
CVE-2007-2500EPSS 5%
server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of…
Flash Player
after 0.7.2
MEDIUM 6.6
CVE-2006-7151
Untrusted search path vulnerability in the libtool-ltdl library (libltdl.so) 1.5.22-2.3 in Fedora Core 5 might allow local users to execute arbitrary…
Libtool Ltdl
Mitigation only
MEDIUM 5.0
CVE-2007-1263EPSS 5%
GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP…
Gpgme
after 1.4.6
MEDIUM 5.0
CVE-2007-1269
GNUMail 1.1.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents GNUMail from visually distinguishing bet…
Gnumail
after 1.1.2
MEDIUM 5.0
CVE-2006-6719
The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (applicat…
Wget
No fix yet