Skip to main content

Vendor archive

gentoo CVEs

Beta · best-effort

197 CVEs tagged to vendor gentoo37 Critical, 57 High, 72 Medium, 31 Low, 0 Unrated.

CVE-2013-2031

Published Nov 18, 2013

MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 e…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1159

Published Oct 28, 2013

Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4893

Published Sep 11, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2983

Published Sep 11, 2012

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2982

Published Sep 11, 2012

file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) cha…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2981

Published Sep 11, 2012

Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1550

Published Mar 30, 2011

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1549

Published Mar 30, 2011

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1548

Published Mar 30, 2011

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to cond…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1155

Published Mar 30, 2011

The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline)…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1154

Published Mar 30, 2011

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filen…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1098

Published Mar 30, 2011

Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-6756

Published Apr 27, 2009

ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4580

Published Oct 15, 2008

fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4579

Published Oct 15, 2008

The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary f…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4394

Published Oct 10, 2008

Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbit…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1880

Published May 12, 2008

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1734

Published Apr 18, 2008

Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1290

Published Mar 24, 2008

ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1291

Published Mar 24, 2008

ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1292

Published Mar 24, 2008

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1383

Published Mar 18, 2008

The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from t…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1078

Published Feb 29, 2008

expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] te…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 197 CVEsPage 2 of 8