Skip to main content

Vendor/product archive

gentoo / linux CVEs

Beta · best-effort

159 CVEs tagged to gentoo / linux30 Critical, 49 High, 53 Medium, 27 Low, 0 Unrated.

CVE-2024-12086

Published Jan 14, 2025

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a c…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2017-18285

Published Jun 4, 2018

The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitra…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18284

Published Jun 4, 2018

The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by lev…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18226

Published Mar 12, 2018

The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveragi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18225

Published Mar 12, 2018

The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which migh…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14730

Published Sep 25, 2017

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2031

Published Nov 18, 2013

MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 e…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1159

Published Oct 28, 2013

Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1549

Published Mar 30, 2011

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6756

Published Apr 27, 2009

ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1880

Published May 12, 2008

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1734

Published Apr 18, 2008

Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1290

Published Mar 24, 2008

ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1291

Published Mar 24, 2008

ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1292

Published Mar 24, 2008

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1383

Published Mar 18, 2008

The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from t…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 159 CVEsPage 1 of 7