Записи gentoo
198 опубликованных записей вендора gentoo.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 5 · 2,5 %
- Pre-auth RCE
- 52
- С записью об исправлении
- 57,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-732 Incorrect Permission Assignment for Critical Resource7
- CWE-399 Resource Management Errors4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-20 Improper Input Validation4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
198 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2004-0608Готовый эксплойт | The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2nerf arena blast · nerf arena blast | Критическая10,0 | — | 73,5 % | 6 дек. 2004 г. |
62На этой неделе | CVE-2002-1337Proof of concept | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Критическая10,0 | — | 72,6 % | 7 мар. 2003 г. |
61На этой неделе | CVE-2024-12084Proof of concept | Rsync: heap buffer overflow in rsync due to improper checksum length handlingsamba · rsync · CWE-122 | Критическая9,8 | — | 72,1 % | 15 янв. 2025 г. |
60На этой неделе | CVE-2003-0694Готовый эксплойт | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Критическая10,0 | — | 66,2 % | 6 окт. 2003 г. |
59В плане | CVE-2004-1037Готовый эксплойт | The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.twiki · twiki | Критическая10,0 | — | 61,7 % | 1 мар. 2005 г. |
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,5 % | 18 дек. 2023 г. |
50В плане | CVE-2004-0493Proof of concept | The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and papache · http server | Средняя6,4 | — | 84,8 % | 6 авг. 2004 г. |
49В плане | CVE-2004-0932Proof of concept | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attacca · etrust antivirus | Высокая7,5 | — | 63,6 % | 27 янв. 2005 г. |
48В плане | CVE-2004-0990Proof of concept | Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of sergd graphics library · gdlib | Критическая10,0 | — | 28,3 % | 1 мар. 2005 г. |
48В плане | CVE-2004-0386Proof of concept | Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a lmplayer · mplayer | Критическая10,0 | — | 27,0 % | 4 мая 2004 г. |
48В плане | CVE-2004-0557Proof of concept | Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers tsox · sox | Критическая10,0 | — | 25,1 % | 6 авг. 2004 г. |
47В плане | CVE-2004-0333Proof of concept | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackersuudeview · uudeview | Критическая10,0 | — | 24,2 % | 23 нояб. 2004 г. |
46В плане | CVE-2007-2194Proof of concept | Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a lgentoo · xnview | Критическая10,0 | — | 18,9 % | 24 апр. 2007 г. |
45В плане | CVE-2012-2982Готовый эксплойт | file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathgentoo · webmin | Средняя6,5 | — | 62,2 % | 11 сент. 2012 г. |
44В плане | CVE-2004-0416Proof of concept | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Критическая10,0 | — | 13,2 % | 6 авг. 2004 г. |
43В плане | CVE-2004-1304Proof of concept | Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file · file | Критическая10,0 | — | 11,4 % | 10 янв. 2005 г. |
43В плане | CVE-2004-0888Эксплойта нет | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Критическая10,0 | — | 9,5 % | 27 янв. 2005 г. |
43В плане | CVE-2004-0914Эксплойта нет | Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)lesstif · lesstif | Критическая10,0 | — | 8,7 % | 10 янв. 2005 г. |
42В плане | CVE-2004-1029Proof of concept | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restsun · jdk · CWE-264 | Критическая9,3 | — | 17,0 % | 1 мар. 2005 г. |
42В плане | CVE-2004-0947Эксплойта нет | Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.arj software inc. · unarj | Критическая10,0 | — | 7,4 % | 9 февр. 2005 г. |
42В плане | CVE-2004-0891Эксплойта нет | Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) rob flynn · gaim | Критическая10,0 | — | 6,9 % | 27 янв. 2005 г. |
42В плане | CVE-2004-0889Эксплойта нет | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Критическая10,0 | — | 6,2 % | 27 янв. 2005 г. |
42В плане | CVE-2004-0981Эксплойта нет | Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain imagimagemagick · imagemagick | Критическая10,0 | — | 5,8 % | 9 февр. 2005 г. |
42В плане | CVE-2004-1034Эксплойта нет | Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to kaffeine · kaffeine player | Критическая10,0 | — | 5,7 % | 1 мар. 2005 г. |
42В плане | CVE-2004-0418Эксплойта нет | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attcvs · cvs | Критическая10,0 | — | 5,7 % | 6 авг. 2004 г. |
- CVE-2004-060862На этой неделе
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2
КритическаяCVSS 10,0Готовый эксплойтEPSS 74 %nerf arena blast · nerf arena blast6 дек. 2004 г.
- CVE-2002-133762На этой неделе
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
КритическаяCVSS 10,0Proof of conceptEPSS 73 %sendmail · sendmail7 мар. 2003 г.
- CVE-2024-1208461На этой неделе
Rsync: heap buffer overflow in rsync due to improper checksum length handling
КритическаяCVSS 9,8Proof of conceptEPSS 72 %samba · rsync15 янв. 2025 г.
- CVE-2003-069460На этой неделе
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %sendmail · advanced message server6 окт. 2003 г.
- CVE-2004-103759В плане
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
КритическаяCVSS 10,0Готовый эксплойтEPSS 62 %twiki · twiki1 мар. 2005 г.
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 94 %ssh · ssh18 дек. 2023 г.
- CVE-2004-049350В плане
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and p
СредняяCVSS 6,4Proof of conceptEPSS 85 %apache · http server6 авг. 2004 г.
- CVE-2004-093249В плане
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attac
ВысокаяCVSS 7,5Proof of conceptEPSS 64 %ca · etrust antivirus27 янв. 2005 г.
- CVE-2004-099048В плане
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of ser
КритическаяCVSS 10,0Proof of conceptEPSS 28 %gd graphics library · gdlib1 мар. 2005 г.
- CVE-2004-038648В плане
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a l
КритическаяCVSS 10,0Proof of conceptEPSS 27 %mplayer · mplayer4 мая 2004 г.
- CVE-2004-055748В плане
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers t
КритическаяCVSS 10,0Proof of conceptEPSS 25 %sox · sox6 авг. 2004 г.
- CVE-2004-033347В плане
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers
КритическаяCVSS 10,0Proof of conceptEPSS 24 %uudeview · uudeview23 нояб. 2004 г.
- CVE-2007-219446В плане
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a l
КритическаяCVSS 10,0Proof of conceptEPSS 19 %gentoo · xnview24 апр. 2007 г.
- CVE-2012-298245В плане
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a path
СредняяCVSS 6,5Готовый эксплойтEPSS 62 %gentoo · webmin11 сент. 2012 г.
- CVE-2004-041644В плане
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
КритическаяCVSS 10,0Proof of conceptEPSS 13 %cvs · cvs6 авг. 2004 г.
- CVE-2004-130443В плане
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF
КритическаяCVSS 10,0Proof of conceptEPSS 11 %file · file10 янв. 2005 г.
- CVE-2004-088843В плане
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %kde · koffice27 янв. 2005 г.
- CVE-2004-091443В плане
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %lesstif · lesstif10 янв. 2005 г.
- CVE-2004-102942В плане
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly rest
КритическаяCVSS 9,3Proof of conceptEPSS 17 %sun · jdk1 мар. 2005 г.
- CVE-2004-094742В плане
Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %arj software inc. · unarj9 февр. 2005 г.
- CVE-2004-089142В плане
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash)
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %rob flynn · gaim27 янв. 2005 г.
- CVE-2004-088942В плане
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %xpdf · xpdf27 янв. 2005 г.
- CVE-2004-098142В плане
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain imag
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %imagemagick · imagemagick9 февр. 2005 г.
- CVE-2004-103442В плане
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %kaffeine · kaffeine player1 мар. 2005 г.
- CVE-2004-041842В плане
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %cvs · cvs6 авг. 2004 г.