openpkg records
27 published records for vendor openpkg.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.7%
- Pre-auth RCE
- 15
- With a fix record
- 88.9%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read1
- CWE-131 Incorrect Calculation of Buffer Size1
- CWE-193 Off-by-one Error1
- CWE-20 Improper Input Validation1
- CWE-203 Observable Discrepancy1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
48Plan | CVE-2004-0990Proof of concept | Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of sergd graphics library · gdlib | Critical10.0 | — | 28.3% | Mar 1, 2005 |
47Plan | CVE-2004-0333Proof of concept | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackersuudeview · uudeview | Critical10.0 | — | 24.2% | Nov 23, 2004 |
44Plan | CVE-2004-0416Proof of concept | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Critical10.0 | — | 13.2% | Aug 6, 2004 |
43Plan | CVE-2003-0190Weaponized | OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, whichopenbsd · openssh · CWE-203 | Medium5.0 | — | 76.8% | May 12, 2003 |
43Plan | CVE-2002-0083Proof of concept | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.immunix · immunix · CWE-193 | Critical9.8 | — | 14.7% | Mar 15, 2002 |
43Plan | CVE-2004-1065No exploit | Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary codphp · php | Critical10.0 | — | 10.0% | Jan 10, 2005 |
42Plan | CVE-2004-1019No exploit | The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitphp · php · CWE-20 | Critical10.0 | — | 8.0% | Jan 10, 2005 |
42Plan | CVE-2004-1012No exploit | The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Critical10.0 | — | 6.0% | Jan 10, 2005 |
42Plan | CVE-2004-0413No exploit | libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allowsubversion · subversion | Critical10.0 | — | 5.9% | Aug 6, 2004 |
42Plan | CVE-2004-1011No exploit | Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execcarnegie mellon university · cyrus imap server | Critical10.0 | — | 5.8% | Jan 10, 2005 |
42Plan | CVE-2004-1013No exploit | The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Critical10.0 | — | 5.8% | Jan 10, 2005 |
42Plan | CVE-2004-0418No exploit | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attcvs · cvs | Critical10.0 | — | 5.7% | Aug 6, 2004 |
41Plan | CVE-2004-0772No exploit | Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execmit · kerberos 5 · CWE-415 | Critical9.8 | — | 7.0% | Oct 20, 2004 |
41Plan | CVE-2004-0414No exploit | CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator frcvs · cvs | Critical10.0 | — | 4.0% | Aug 6, 2004 |
36Monitor | CVE-2004-0594Proof of concept | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enahp · hp-ux · CWE-367 | Medium5.1 | — | 54.9% | Jul 27, 2004 |
32Monitor | CVE-2004-0940Proof of concept | Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to executeapache · http server · CWE-131 | High7.8 | — | 4.8% | Feb 9, 2005 |
31Monitor | CVE-2007-5116No exploit | Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackerdebian · debian linux · CWE-119 | High7.5 | — | 4.8% | Nov 7, 2007 |
31Monitor | CVE-2005-0373No exploit | Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bucyrus · sasl | High7.5 | — | 3.9% | Oct 7, 2004 |
31Monitor | CVE-2002-0985No exploit | Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify cphp · php · CWE-88 | High7.5 | — | 3.0% | Sep 24, 2002 |
30Monitor | CVE-2004-1471Proof of concept | Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commicvs · cvs | High7.1 | — | 7.7% | Dec 31, 2004 |
28Monitor | CVE-2004-0957No exploit | Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), openpkg · openpkg | Medium6.8 | — | 2.4% | Feb 9, 2005 |
25Monitor | CVE-2004-0918No exploit | The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a desquid · squid · CWE-399 | Medium5.0 | — | 15.8% | Jan 27, 2005 |
22Monitor | CVE-2003-0147No exploit | OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factopenssl · openssl | Medium5.0 | — | 6.4% | Mar 31, 2003 |
21Monitor | CVE-2004-0421No exploit | The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG libpng · libpng · CWE-125 | Medium5.0 | — | 4.1% | Aug 18, 2004 |
21Monitor | CVE-2004-0417No exploit | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may cvs · cvs | Medium5.0 | — | 3.1% | Aug 6, 2004 |
- CVE-2004-099048Plan
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of ser
CriticalCVSS 10.0Proof of conceptEPSS 28%gd graphics library · gdlibMar 1, 2005
- CVE-2004-033347Plan
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers
CriticalCVSS 10.0Proof of conceptEPSS 24%uudeview · uudeviewNov 23, 2004
- CVE-2004-041644Plan
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
CriticalCVSS 10.0Proof of conceptEPSS 13%cvs · cvsAug 6, 2004
- CVE-2003-019043Plan
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which
MediumCVSS 5.0WeaponizedEPSS 77%openbsd · opensshMay 12, 2003
- CVE-2002-008343Plan
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
CriticalCVSS 9.8Proof of conceptEPSS 15%immunix · immunixMar 15, 2002
- CVE-2004-106543Plan
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary cod
CriticalCVSS 10.0No exploitEPSS 10%php · phpJan 10, 2005
- CVE-2004-101942Plan
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbit
CriticalCVSS 10.0No exploitEPSS 8%php · phpJan 10, 2005
- CVE-2004-101242Plan
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2004-041342Plan
libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allow
CriticalCVSS 10.0No exploitEPSS 6%subversion · subversionAug 6, 2004
- CVE-2004-101142Plan
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2004-101342Plan
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2004-041842Plan
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att
CriticalCVSS 10.0No exploitEPSS 6%cvs · cvsAug 6, 2004
- CVE-2004-077241Plan
Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec
CriticalCVSS 9.8No exploitEPSS 7%mit · kerberos 5Oct 20, 2004
- CVE-2004-041441Plan
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator fr
CriticalCVSS 10.0No exploitEPSS 4%cvs · cvsAug 6, 2004
- CVE-2004-059436Monitor
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is ena
MediumCVSS 5.1Proof of conceptEPSS 55%hp · hp-uxJul 27, 2004
- CVE-2004-094032Monitor
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute
HighCVSS 7.8Proof of conceptEPSS 5%apache · http serverFeb 9, 2005
- CVE-2007-511631Monitor
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attacker
HighCVSS 7.5No exploitEPSS 5%debian · debian linuxNov 7, 2007
- CVE-2005-037331Monitor
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu
HighCVSS 7.5No exploitEPSS 4%cyrus · saslOct 7, 2004
- CVE-2002-098531Monitor
Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify c
HighCVSS 7.5No exploitEPSS 3%php · phpSep 24, 2002
- CVE-2004-147130Monitor
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commi
HighCVSS 7.1Proof of conceptEPSS 8%cvs · cvsDec 31, 2004
- CVE-2004-095728Monitor
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore),
MediumCVSS 6.8No exploitEPSS 2%openpkg · openpkgFeb 9, 2005
- CVE-2004-091825Monitor
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de
MediumCVSS 5.0No exploitEPSS 16%squid · squidJan 27, 2005
- CVE-2003-014722Monitor
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining fact
MediumCVSS 5.0No exploitEPSS 6%openssl · opensslMar 31, 2003
- CVE-2004-042121Monitor
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG
MediumCVSS 5.0No exploitEPSS 4%libpng · libpngAug 18, 2004
- CVE-2004-041721Monitor
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may
MediumCVSS 5.0No exploitEPSS 3%cvs · cvsAug 6, 2004