Skip to main content

Vendor archive

gentoo CVEs

Beta · best-effort

197 CVEs tagged to vendor gentoo37 Critical, 57 High, 72 Medium, 31 Low, 0 Unrated.

CVE-2004-1030

Published Mar 1, 2005

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1031

Published Mar 1, 2005

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid proc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1032

Published Mar 1, 2005

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large nu…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1033

Published Mar 1, 2005

Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny v…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1034

Published Mar 1, 2005

Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1036

Published Mar 1, 2005

Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1037

Published Mar 1, 2005

The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1052

Published Mar 1, 2005

Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that cont…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1055

Published Mar 1, 2005

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri pa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0535

Published Feb 22, 2005

Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0969

Published Feb 9, 2005

The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overw…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0888

Published Jan 27, 2005

Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cra…

CVSS 10.0 · Critical

CVE-2004-0889

Published Jan 27, 2005

Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitr…

CVSS 10.0 · Critical
Showing 101-125 of 197 CVEsPage 5 of 8