rpath records
19 published records for vendor rpath.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 63.2%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-399 Resource Management Errors2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2006-6235No exploit | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute argnu · privacy guard | Critical10.0 | — | 5.9% | Dec 7, 2006 |
36Monitor | CVE-2007-1351No exploit | Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allx.org · libxfont · CWE-189 | High8.5 | — | 5.6% | Apr 5, 2007 |
32Monitor | CVE-2007-5962Proof of concept | Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresighredhat · enterprise linux · CWE-399 | High7.1 | — | 12.1% | May 22, 2008 |
31Monitor | CVE-2008-0411Proof of concept | Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrghostscript · ghostscript · CWE-119 | Medium6.8 | — | 14.5% | Feb 28, 2008 |
31Monitor | CVE-2007-5116No exploit | Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackerdebian · debian linux · CWE-119 | High7.5 | — | 4.8% | Nov 7, 2007 |
31Monitor | CVE-2008-5516No exploit | The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related git · git · CWE-78 | High7.5 | — | 4.4% | Jan 20, 2009 |
28Monitor | CVE-2007-3106No exploit | lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service andlibvorbis · libvorbis · CWE-399 | Medium6.8 | — | 3.1% | Jul 26, 2007 |
28Monitor | CVE-2007-4131No exploit | Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrgnu · tar | Medium6.8 | — | 2.7% | Aug 24, 2007 |
28Monitor | CVE-2008-1078No exploit | expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files vgentoo · linux · CWE-59 | High7.2 | — | 0.5% | Feb 28, 2008 |
28Monitor | CVE-2007-0536No exploit | The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissirpath · rpath linux | High7.2 | — | 0.4% | Jan 26, 2007 |
27Monitor | CVE-2007-4029No exploit | libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalilibvorbis · libvorbis | Medium6.8 | — | 1.7% | Jul 26, 2007 |
27Monitor | CVE-2007-5194No exploit | The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device nrpath · rmake · CWE-264 | Medium6.9 | — | 0.3% | Oct 4, 2007 |
27Monitor | CVE-2008-4832No exploit | rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directorrpath · initscripts · CWE-59 | Medium6.9 | — | 0.3% | Nov 17, 2008 |
26Monitor | CVE-2008-2139No exploit | The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session,rpath · appliance platform agent · CWE-264 | Medium6.5 | — | 0.4% | May 12, 2008 |
21Monitor | CVE-2008-3139No exploit | The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via uwireshark · wireshark · CWE-200 | Medium5.0 | — | 2.9% | Jul 10, 2008 |
21Monitor | CVE-2008-3138No exploit | The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of serwireshark · wireshark · CWE-200 | Medium5.0 | — | 2.0% | Jul 10, 2008 |
19Monitor | CVE-2007-5686No exploit | initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information rpath · rpath linux · CWE-264 | Medium4.9 | — | 0.9% | Oct 28, 2007 |
15Monitor | CVE-2007-1352No exploit | Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary x.org · libxfont | Low3.8 | — | 1.5% | Apr 5, 2007 |
10Monitor | CVE-2008-2140No exploit | Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to rerpath · appliance platform agent · CWE-352 | Low2.6 | — | 0.4% | May 12, 2008 |
- CVE-2006-623542Plan
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar
CriticalCVSS 10.0No exploitEPSS 6%gnu · privacy guardDec 7, 2006
- CVE-2007-135136Monitor
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier all
HighCVSS 8.5No exploitEPSS 6%x.org · libxfontApr 5, 2007
- CVE-2007-596232Monitor
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresigh
HighCVSS 7.1Proof of conceptEPSS 12%redhat · enterprise linuxMay 22, 2008
- CVE-2008-041131Monitor
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitr
MediumCVSS 6.8Proof of conceptEPSS 15%ghostscript · ghostscriptFeb 28, 2008
- CVE-2007-511631Monitor
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attacker
HighCVSS 7.5No exploitEPSS 5%debian · debian linuxNov 7, 2007
- CVE-2008-551631Monitor
The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related
HighCVSS 7.5No exploitEPSS 4%git · gitJan 20, 2009
- CVE-2007-310628Monitor
lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and
MediumCVSS 6.8No exploitEPSS 3%libvorbis · libvorbisJul 26, 2007
- CVE-2007-413128Monitor
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwr
MediumCVSS 6.8No exploitEPSS 3%gnu · tarAug 24, 2007
- CVE-2008-107828Monitor
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files v
HighCVSS 7.2No exploitEPSS 1%gentoo · linuxFeb 28, 2008
- CVE-2007-053628Monitor
The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissi
HighCVSS 7.2No exploitEPSS 0%rpath · rpath linuxJan 26, 2007
- CVE-2007-402927Monitor
libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invali
MediumCVSS 6.8No exploitEPSS 2%libvorbis · libvorbisJul 26, 2007
- CVE-2007-519427Monitor
The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device n
MediumCVSS 6.9No exploitEPSS 0%rpath · rmakeOct 4, 2007
- CVE-2008-483227Monitor
rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a director
MediumCVSS 6.9No exploitEPSS 0%rpath · initscriptsNov 17, 2008
- CVE-2008-213926Monitor
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session,
MediumCVSS 6.5No exploitEPSS 0%rpath · appliance platform agentMay 12, 2008
- CVE-2008-313921Monitor
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via u
MediumCVSS 5.0No exploitEPSS 3%wireshark · wiresharkJul 10, 2008
- CVE-2008-313821Monitor
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of ser
MediumCVSS 5.0No exploitEPSS 2%wireshark · wiresharkJul 10, 2008
- CVE-2007-568619Monitor
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information
MediumCVSS 4.9No exploitEPSS 1%rpath · rpath linuxOct 28, 2007
- CVE-2007-135215Monitor
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary
LowCVSS 3.8No exploitEPSS 2%x.org · libxfontApr 5, 2007
- CVE-2008-214010Monitor
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to re
LowCVSS 2.6No exploitEPSS 0%rpath · appliance platform agentMay 12, 2008