VYPR

by GNU

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2001-10360.030.00Aug 31, 2001GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
CVE-2007-24520.000.02Jun 4, 2007Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.