VYPR

Vendor CVEs

GNU

All CVEs

1,358 total · sorted by risk
  • CVE-2005-1705May 24, 2005
    risk 0.00cvss epss 0.00

    gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.

  • CVE-2005-1704May 24, 2005
    risk 0.00cvss epss 0.01

    Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a…

  • CVE-2005-0758May 13, 2005
    risk 0.00cvss epss 0.01

    zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.

  • CVE-2005-1431May 3, 2005
    risk 0.00cvss epss 0.02

    The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.

  • CVE-2005-1039May 2, 2005
    risk 0.00cvss epss 0.00

    Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.

  • CVE-2005-0990May 2, 2005
    risk 0.00cvss epss 0.00

    unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.

  • CVE-2005-1229May 2, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.

  • CVE-2005-0202May 2, 2005
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./"…

  • CVE-2005-1228May 2, 2005
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.

  • CVE-2005-0080May 2, 2005
    risk 0.00cvss epss 0.01

    The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.

  • CVE-2005-0988May 2, 2005
    risk 0.00cvss epss 0.01

    Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is…

  • CVE-2004-1487Apr 27, 2005
    risk 0.00cvss epss 0.02

    wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.

  • CVE-2004-0970Feb 9, 2005
    risk 0.00cvss epss 0.00

    The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.

  • CVE-2004-0968Feb 9, 2005
    risk 0.00cvss epss 0.00

    The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.

  • CVE-2004-0969Feb 9, 2005
    risk 0.00cvss epss 0.00

    The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

  • CVE-2004-0966Feb 9, 2005
    risk 0.00cvss epss 0.00

    The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

  • CVE-2005-0100Feb 7, 2005
    risk 0.00cvss epss 0.04

    Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

  • CVE-2004-1184Jan 21, 2005
    risk 0.00cvss epss 0.01

    The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.

  • CVE-2004-1185Jan 21, 2005
    risk 0.00cvss epss 0.04

    Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.

  • CVE-2004-1177Jan 10, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

  • CVE-2004-2459Dec 31, 2004
    risk 0.00cvss epss 0.01

    Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.

  • CVE-2004-1772Dec 31, 2004
    risk 0.00cvss epss 0.01

    Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.

  • CVE-2004-1773Dec 31, 2004
    risk 0.00cvss epss 0.03

    Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.

  • CVE-2004-1186Dec 31, 2004
    risk 0.00cvss epss 0.04

    Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).

  • CVE-2004-0555Dec 31, 2004
    risk 0.00cvss epss 0.03

    Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.

  • CVE-2004-1382Dec 31, 2004
    risk 0.00cvss epss 0.00

    The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.

  • CVE-2004-0984Dec 31, 2004
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.

  • CVE-2004-2264Dec 31, 2004
    risk 0.00cvss epss 0.02

    Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid,…

  • CVE-2004-2531Dec 31, 2004
    risk 0.00cvss epss 0.02

    X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys.

  • CVE-2004-1143Dec 31, 2004
    risk 0.00cvss epss 0.02

    The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.

  • CVE-2004-2461Dec 31, 2004
    risk 0.00cvss epss 0.03

    Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code.

  • CVE-2004-1453Dec 31, 2004
    risk 0.00cvss epss 0.00

    GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.

  • CVE-2004-2460Dec 31, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.

  • CVE-2004-1377Dec 27, 2004
    risk 0.00cvss epss 0.00

    The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2004-0849Dec 23, 2004
    risk 0.00cvss epss 0.02

    Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.

  • CVE-2004-1337Dec 23, 2004
    risk 0.00cvss epss 0.00

    The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.

  • CVE-2004-0603Dec 6, 2004
    risk 0.00cvss epss 0.03

    gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332.

  • CVE-2004-0623Dec 6, 2004
    risk 0.00cvss epss 0.04

    Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

  • CVE-2004-0576Dec 6, 2004
    risk 0.00cvss epss 0.02

    The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing an invalid OID.

  • CVE-2004-0256Nov 23, 2004
    risk 0.00cvss epss 0.00

    GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.

  • CVE-2004-0778Oct 20, 2004
    risk 0.00cvss epss 0.02

    CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows remote attackers to determine the existence of arbitrary files and directories via the -X command for an alternate history file, which causes different error messages to be returned.

  • CVE-2004-1349Oct 4, 2004
    risk 0.00cvss epss 0.01

    gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.

  • CVE-2004-0412Aug 18, 2004
    risk 0.00cvss epss 0.03

    Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.

  • CVE-2004-1702Aug 9, 2004
    risk 0.00cvss epss 0.02

    The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of…

  • CVE-2004-0581Aug 6, 2004
    risk 0.00cvss epss 0.00

    ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.

  • CVE-2004-0422Jul 7, 2004
    risk 0.00cvss epss 0.00

    flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.

  • CVE-2004-0182Jun 1, 2004
    risk 0.00cvss epss 0.01

    Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.

  • CVE-2003-0991Mar 3, 2004
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.

  • CVE-2004-0131Mar 3, 2004
    risk 0.00cvss epss 0.04

    The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null…

  • CVE-2003-0992Feb 17, 2004
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.