Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Portage HIGH 7.1
CVE-2004-2778

Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to…

Mitigation only
Fix from $1,950 2017-06-27
Xdg Utils MEDIUM 6.8
CVE-2014-9622

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execu…

No fix yet
Fix from $1,600 2015-01-21
Nullmailer MEDIUM 5.0
CVE-2013-4223

The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP aut…

Mitigation only
Fix from $1,600 2014-05-23
Logrotate MEDIUM 6.3
CVE-2011-1548

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, wh…

Mitigation only
Fix from $1,600 2011-03-30
Logrotate MEDIUM 6.3
CVE-2011-1549

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which …

Mitigation only
Fix from $1,600 2011-03-30
Logrotate MEDIUM 6.3
CVE-2011-1550

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write acces…

Mitigation only
Fix from $1,600 2011-03-30
Cman HIGH 7.2
CVE-2008-4580

fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fi…

Mitigation only
Fix from $1,950 2008-10-15
Linux HIGH 7.2
CVE-2008-1078

expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a syml…

No fix yet
Fix from $1,950 2008-02-29
Xnview HIGH 10.0
CVE-2007-2194EPSS 19%

Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long secti…

No fix yet
Fix from $1,950 2007-04-24
Linux MEDIUM 6.8
CVE-2004-1055

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML…

No fix yet
Fix from $1,600 2005-03-01
Linux HIGH 10.0
CVE-2004-0891EPSS 7%

Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possi…

Mitigation only
Fix from $1,950 2005-01-27
Linux HIGH 7.2
CVE-2004-0834

Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) …

Mitigation only
Fix from $1,950 2004-12-23
Linux HIGH 7.2
CVE-2004-0496

Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities…

Mitigation only
Fix from $1,950 2004-12-06
Linux MEDIUM 5.0
CVE-2004-0232

Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary …

Mitigation only
Fix from $1,600 2004-08-18
Linux HIGH 7.2
CVE-2004-0548

Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code vi…

Mitigation only
Fix from $1,950 2004-08-06
Linux HIGH 7.5
CVE-2004-0700EPSS 6%

Format string vulnerability in the mod_proxy hook functions function in ssl_engine_log.c in mod_ssl before 2.8.19 for Apache before 1.3.31 may allow …

Mitigation only
Fix from $1,950 2004-07-27