Skip to main content

Vendor archive

gentoo CVEs

Beta · best-effort

197 CVEs tagged to vendor gentoo37 Critical, 57 High, 72 Medium, 31 Low, 0 Unrated.

CVE-2007-6337

Published Dec 31, 2007

Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6249

Published Dec 15, 2007

etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original f…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5714

Published Oct 30, 2007

The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login acces…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3532

Published Jul 27, 2007

NVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11, as used in Gentoo Linux and possibly other distributions, creates /dev/nvidia* device files with insecure…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3531

Published Jul 25, 2007

The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock tempor…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3508

Published Jul 3, 2007

Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment vari…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2194

Published Apr 24, 2007

Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of thes…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1856

Published Apr 18, 2007

Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, whic…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-2026

Published Apr 13, 2007

The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line f…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1500

Published Mar 19, 2007

The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7094

Published Mar 2, 2007

ftpd, as used by Gentoo and Debian Linux, sets the gid to the effective uid instead of the effective group id before executing /bin/ls, which allows remote authenticated users to…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1049

Published Feb 21, 2007

Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/functions.php) for WordPress 2.0 before 2.0.9 and 2.1 before…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0476

Published Jan 25, 2007

The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary direc…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3005

Published Jun 13, 2006

The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1390

Published Mar 25, 2006

The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modif…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0071

Published Jan 4, 2006

The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4595

Published Dec 31, 2005

Untrusted search path vulnerability (RPATH) in XnView 1.70 and NView 4.51 on Gentoo Linux allows local users to execute arbitrary code via a malicious library in the current worki…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4279

Published Dec 16, 2005

Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3785

Published Nov 23, 2005

Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync te…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 197 CVEsPage 3 of 8