cdrtools records
4 published records for vendor cdrtools.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
29Monitor | CVE-2004-0806Proof of concept | cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specicdrtools · cdrecord | High7.2 | — | 1.7% | Dec 31, 2004 |
28Monitor | CVE-2003-0289Proof of concept | Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string spcdrtools · cdrecord | High7.2 | — | 1.1% | Jun 16, 2003 |
28Monitor | CVE-2003-0655Proof of concept | rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file ascdrtools · cdrtools | High7.2 | — | 0.7% | Aug 27, 2003 |
8Monitor | CVE-2005-0866No exploit | cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.cdrtools · cdrecord | Low2.1 | — | 0.3% | May 2, 2005 |
- CVE-2004-080629Monitor
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program speci
HighCVSS 7.2Proof of conceptEPSS 2%cdrtools · cdrecordDec 31, 2004
- CVE-2003-028928Monitor
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string sp
HighCVSS 7.2Proof of conceptEPSS 1%cdrtools · cdrecordJun 16, 2003
- CVE-2003-065528Monitor
rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as
HighCVSS 7.2Proof of conceptEPSS 1%cdrtools · cdrtoolsAug 27, 2003
- CVE-2005-08668Monitor
cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
LowCVSS 2.1No exploitEPSS 0%cdrtools · cdrecordMay 2, 2005