Skip to main content

Vendor/product archive

gnu / groff CVEs

Beta · best-effort

11 CVEs tagged to gnu / groff1 Critical, 2 High, 1 Medium, 7 Low, 0 Unrated.

CVE-2009-5082

Published Jun 30, 2011

The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp fun…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5081

Published Jun 30, 2011

The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5080

Published Jun 30, 2011

The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not prope…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5079

Published Jun 30, 2011

The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files v…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5078

Published Jun 30, 2011

contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, re…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5044

Published Jun 24, 2011

contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0969

Published Feb 9, 2005

The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overw…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1296

Published Dec 31, 2004

The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-0003

Published Feb 27, 2002

Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1022

Published Jul 26, 2001

Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary comman…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0803

Published Dec 19, 2000

GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1