Gentoo / Linux
136 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-12084 | Rsync: heap buffer overflow in rsync due to improper checksum length handling | CRITICAL | 9.8 | Jan 15, 2025 |
| CVE-2024-12087 | Rsync: path traversal vulnerability in rsync | HIGH | 7.5 | Jan 14, 2025 |
| CVE-2024-12088 | Rsync: --safe-links option bypass leads to path traversal | HIGH | 7.5 | Jan 14, 2025 |
| CVE-2024-12086 | Rsync: rsync server leaks arbitrary client files | MEDIUM | 6.8 | Jan 14, 2025 |
| CVE-2024-12085 | Rsync: info leak via uninitialized stack contents | HIGH | 7.5 | Jan 14, 2025 |
| CVE-2014-4909 | Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service… | MEDIUM | 6.8 | Jul 29, 2014 |
| CVE-2013-0348 | thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive info… | LOW | 2.1 | Dec 13, 2013 |
| CVE-2013-2032 | MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:Cha… | MEDIUM | 5.0 | Nov 15, 2013 |
| CVE-2013-2031 | MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section cont… | MEDIUM | 4.3 | Nov 15, 2013 |
| CVE-2010-1159 | Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1)… | MEDIUM | 6.8 | Oct 28, 2013 |
| CVE-2008-1383 | The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to ex… | LOW | 1.9 | Mar 18, 2008 |
| CVE-2008-1078 | am-utils: insecure usage of temporary files | HIGH | 7.2 | Feb 29, 2008 |
| CVE-2007-1500 | The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsa… | MEDIUM | 4.3 | Mar 19, 2007 |
| CVE-2007-0476 | The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not cr… | MEDIUM | 4.6 | Jan 25, 2007 |
| CVE-2006-3005 | The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a… | MEDIUM | 5.0 | Jun 13, 2006 |
| CVE-2006-1390 | nethack: Local privilege escalation via crafted score file | MEDIUM | 4.6 | Mar 25, 2006 |
| CVE-2005-3626 | security flaw | MEDIUM | 5.0 | Jan 6, 2006 |
| CVE-2005-3625 | security flaw | HIGH | 10.0 | Jan 6, 2006 |
| CVE-2005-3624 | security flaw | MEDIUM | 5.0 | Jan 6, 2006 |
| CVE-2006-0071 | The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files a… | MEDIUM | 6.6 | Jan 4, 2006 |
| CVE-2005-2557 | Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML… | MEDIUM | 4.3 | Sep 28, 2005 |
| CVE-2005-1267 | security flaw | MEDIUM | 5.0 | Jun 20, 2005 |
| CVE-2004-1983 | The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local… | LOW | 2.1 | May 10, 2005 |
| CVE-2004-1901 | Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles. | MEDIUM | 5.5 | May 10, 2005 |
| CVE-2004-1307 | security flaw | HIGH | 7.5 | May 4, 2005 |
Showing 1 to 25 of 136 CVEs