Vulnerability index

Browse CVEs

102 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ebuild For Slurm CRITICAL 9.8
CVE-2020-36770

pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem…

Fix: after 22.05.3
Fix from $2,300 2024-01-15
Portage CRITICAL 9.8
CVE-2016-20021

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does n…

Fix: 3.0.47+
Fix from $2,300 2024-01-12
Soko CRITICAL 9.8
CVE-2023-28424

Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in …

Fix: 1.0.2+
Fix from $2,300 2023-03-20
Soko CRITICAL 9.1
CVE-2023-26033

Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injection, leading to a Denial of Service. If …

Fix: 1.0.1+
Fix from $2,300 2023-02-25
Portage MEDIUM 5.5
CVE-2019-20384

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to th…

Fix: after 2.3.84
Fix from $1,600 2020-01-21
Sci Mathematics Gimps HIGH 7.3
CVE-2017-14484

The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by cr…

Patch available
Fix from $1,950 2017-09-15
Dev Python Flower MEDIUM 5.5
CVE-2017-14483

flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-root account, which might all…

Fix: after 0.9.1
Fix from $1,600 2017-09-15
Portage HIGH 7.1
CVE-2004-2778

Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to…

Mitigation only
Fix from $1,950 2017-06-27
Xdg Utils MEDIUM 6.8
CVE-2014-9622

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execu…

No fix yet
Fix from $1,600 2015-01-21
Portage HIGH 9.3
CVE-2013-2100

The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers,…

Patch available
Fix from $1,950 2014-09-29
Nullmailer MEDIUM 5.0
CVE-2013-4223

The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP aut…

Mitigation only
Fix from $1,600 2014-05-23
Linux MEDIUM 6.8
CVE-2010-1159EPSS 7%

Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code…

Fix: after 1.0
Fix from $1,600 2013-10-28
Webmin MEDIUM 6.8
CVE-2012-4893

Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authenti…

Fix: after 1.590
Fix from $1,600 2012-09-11
Webmin MEDIUM 6.5
CVE-2012-2982EPSS 62%

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as …

Fix: after 1.590
Fix from $1,600 2012-09-11
Webmin MEDIUM 6.0
CVE-2012-2981

Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor ty…

Fix: after 1.590
Fix from $1,600 2012-09-11
Webmin MEDIUM 5.0
CVE-2012-2983EPSS 20%

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote…

Fix: after 1.590
Fix from $1,600 2012-09-11
Logrotate MEDIUM 6.9
CVE-2011-1154

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell…

Fix: after 3.7.9
Fix from $1,600 2011-03-30
Logrotate MEDIUM 6.3
CVE-2011-1548

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, wh…

Mitigation only
Fix from $1,600 2011-03-30
Logrotate MEDIUM 6.3
CVE-2011-1549

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which …

Mitigation only
Fix from $1,600 2011-03-30
Logrotate MEDIUM 6.3
CVE-2011-1550

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write acces…

Mitigation only
Fix from $1,600 2011-03-30
Cman HIGH 7.2
CVE-2008-4580

fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fi…

Mitigation only
Fix from $1,950 2008-10-15
Portage MEDIUM 6.9
CVE-2008-4394

Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allow…

Fix: after 2.1.4.4
Fix from $1,600 2008-10-10
Linux HIGH 7.2
CVE-2008-1078

expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a syml…

No fix yet
Fix from $1,950 2008-02-29
Xdg Utils MEDIUM 6.8
CVE-2008-0386

Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg…

Fix: after 1.0.2
Fix from $1,600 2008-02-04
Mldonkey Ebuild MEDIUM 6.8
CVE-2007-5714

The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote a…

Fix: after 2.9.0
Fix from $1,600 2007-10-30
Nvclock MEDIUM 6.6
CVE-2007-3531

The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink att…

Fix: after 0.7
Fix from $1,600 2007-07-25
Glibc HIGH 7.2
CVE-2007-3508

Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large …

Fix: after 2.5
Fix from $1,950 2007-07-03
Xnview HIGH 10.0
CVE-2007-2194EPSS 19%

Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long secti…

No fix yet
Fix from $1,950 2007-04-24
Linux MEDIUM 5.0
CVE-2006-3005

The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers …

Patch available
Fix from $1,600 2006-06-13
Linux MEDIUM 6.6
CVE-2006-0071

The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitra…

Patch available
Fix from $1,600 2006-01-04