Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 10.0 CVE-2006-4181 Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execut… Radius Patch available Fix from $1,9502006-11-28 MEDIUM 5.1 CVE-2006-5864EPSS 15% Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to exe… Gv No fix yet Fix from $1,6002006-11-11 HIGH 7.5 CVE-2006-2191 Format string vulnerability in Mailman before 2.1.9 allows attackers to execute arbitrary code via unspecified vectors. NOTE: the vendor has disputed… Mailman after 2.1.8 Fix from $1,9502006-09-19 MEDIUM 5.0 CVE-2006-4790 verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field … Gnutls Patch available Fix from $1,6002006-09-14 MEDIUM 6.8 CVE-2006-3636EPSS 7% Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unsp… Mailman Patch available Fix from $1,6002006-09-06 MEDIUM 5.0 CVE-2006-2941 Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted… Mailman Patch available Fix from $1,6002006-09-06 MEDIUM 5.1 CVE-2006-4146 Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers,… Gdb Patch available Fix from $1,6002006-08-31 HIGH 7.3 CVE-2006-2362EPSS 14% Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-depe… Binutils 2.17+ Fix from $1,9502006-05-15 MEDIUM 5.0 CVE-2006-0052 The attachment scrubber (Scrubber.py) in Mailman 2.1.5 and earlier, when using Python's library email module 2.5, allows remote attackers to cause a … Mailman Patch available Fix from $1,6002006-03-31 MEDIUM 5.0 CVE-2006-0049 gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that i… Privacy Guard Patch available Fix from $1,6002006-03-13 MEDIUM 5.1 CVE-2006-0300EPSS 5% Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code… Tar Patch available Fix from $1,6002006-02-24 HIGH 7.5 CVE-2006-0075 Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via the e-mail field (m… Phpbook after 1.3.2 Fix from $1,9502006-01-04 HIGH 7.8 CVE-2005-4153 Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on ba… Mailman Patch available Fix from $1,9502005-12-11 MEDIUM 6.4 CVE-2005-3355 Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values". Gnump3d Patch available Fix from $1,6002005-11-18 MEDIUM 5.0 CVE-2005-3573 Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to… Mailman Mitigation only Fix from $1,6002005-11-16 MEDIUM 5.0 CVE-2005-3123 Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////… Gnump3d Patch available Fix from $1,6002005-10-30 HIGH 7.5 CVE-2005-2878EPSS 15% Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via for… Mailutils Patch available Fix from $1,9502005-09-13 HIGH 10.0 CVE-2005-2541 Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges. Tar Mitigation only Fix from $1,9502005-08-10 HIGH 7.5 CVE-2005-1824 The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which… Mailutils Patch available Fix from $1,9502005-06-02 HIGH 7.5 CVE-2005-1520EPSS 7% Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote atta… Mailutils Patch available Fix from $1,9502005-05-26 HIGH 7.5 CVE-2005-1521 Integer overflow in the fetch_io function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attacker… Mailutils Patch available Fix from $1,9502005-05-26 HIGH 7.5 CVE-2005-1523EPSS 10% Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbit… Mailutils Patch available Fix from $1,9502005-05-26 MEDIUM 5.0 CVE-2005-1522 The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CP… Mailutils Patch available Fix from $1,6002005-05-26 HIGH 7.2 CVE-2005-1705 gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands… Gdb after 6.3 Fix from $1,9502005-05-24 MEDIUM 5.0 CVE-2005-1431 The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related t… Gnutls Mitigation only Fix from $1,6002005-05-03 MEDIUM 5.0 CVE-2005-0202 Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary fil… Mailman Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-1228 Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot do… Gzip Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2004-1487 wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP … Wget No fix yet Fix from $1,6002005-04-27 MEDIUM 5.0 CVE-2004-1488EPSS 12% wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web… Wget No fix yet Fix from $1,6002005-04-27 HIGH 7.5 CVE-2005-0100 Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows rem… Emacs after 21.4 Fix from $1,9502005-02-07