gentoo kayıtları
gentoo üreticisine ait 198 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 5 · %2,5
- Pre-auth RCE
- 52
- Düzeltme kaydı olan
- %57,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-732 Incorrect Permission Assignment for Critical Resource7
- CWE-399 Resource Management Errors4
- CWE-59 Improper Link Resolution Before File Access ('Link Following')4
- CWE-20 Improper Input Validation4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
198 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2004-0608Silahlaştırılmış | The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2nerf arena blast · nerf arena blast | Kritik10,0 | — | %73,5 | 6 Ara 2004 |
62Bu hafta | CVE-2002-1337Kavram kanıtı | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Kritik10,0 | — | %72,6 | 7 Mar 2003 |
61Bu hafta | CVE-2024-12084Kavram kanıtı | Rsync: heap buffer overflow in rsync due to improper checksum length handlingsamba · rsync · CWE-122 | Kritik9,8 | — | %72,1 | 15 Oca 2025 |
60Bu hafta | CVE-2003-0694Silahlaştırılmış | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Kritik10,0 | — | %66,2 | 6 Eki 2003 |
59Planlayın | CVE-2004-1037Silahlaştırılmış | The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.twiki · twiki | Kritik10,0 | — | %61,7 | 1 Mar 2005 |
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,5 | 18 Ara 2023 |
50Planlayın | CVE-2004-0493Kavram kanıtı | The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and papache · http server | Orta6,4 | — | %84,8 | 6 Ağu 2004 |
49Planlayın | CVE-2004-0932Kavram kanıtı | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attacca · etrust antivirus | Yüksek7,5 | — | %63,6 | 27 Oca 2005 |
48Planlayın | CVE-2004-0990Kavram kanıtı | Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of sergd graphics library · gdlib | Kritik10,0 | — | %28,3 | 1 Mar 2005 |
48Planlayın | CVE-2004-0386Kavram kanıtı | Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a lmplayer · mplayer | Kritik10,0 | — | %27,0 | 4 May 2004 |
48Planlayın | CVE-2004-0557Kavram kanıtı | Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers tsox · sox | Kritik10,0 | — | %25,1 | 6 Ağu 2004 |
47Planlayın | CVE-2004-0333Kavram kanıtı | Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackersuudeview · uudeview | Kritik10,0 | — | %24,2 | 23 Kas 2004 |
46Planlayın | CVE-2007-2194Kavram kanıtı | Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a lgentoo · xnview | Kritik10,0 | — | %18,9 | 24 Nis 2007 |
45Planlayın | CVE-2012-2982Silahlaştırılmış | file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathgentoo · webmin | Orta6,5 | — | %62,2 | 11 Eyl 2012 |
44Planlayın | CVE-2004-0416Kavram kanıtı | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Kritik10,0 | — | %13,2 | 6 Ağu 2004 |
43Planlayın | CVE-2004-1304Kavram kanıtı | Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file · file | Kritik10,0 | — | %11,4 | 10 Oca 2005 |
43Planlayın | CVE-2004-0888İstismar yok | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Kritik10,0 | — | %9,5 | 27 Oca 2005 |
43Planlayın | CVE-2004-0914İstismar yok | Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)lesstif · lesstif | Kritik10,0 | — | %8,7 | 10 Oca 2005 |
42Planlayın | CVE-2004-1029Kavram kanıtı | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restsun · jdk · CWE-264 | Kritik9,3 | — | %17,0 | 1 Mar 2005 |
42Planlayın | CVE-2004-0947İstismar yok | Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.arj software inc. · unarj | Kritik10,0 | — | %7,4 | 9 Şub 2005 |
42Planlayın | CVE-2004-0891İstismar yok | Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) rob flynn · gaim | Kritik10,0 | — | %6,9 | 27 Oca 2005 |
42Planlayın | CVE-2004-0889İstismar yok | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Kritik10,0 | — | %6,2 | 27 Oca 2005 |
42Planlayın | CVE-2004-0981İstismar yok | Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain imagimagemagick · imagemagick | Kritik10,0 | — | %5,8 | 9 Şub 2005 |
42Planlayın | CVE-2004-1034İstismar yok | Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to kaffeine · kaffeine player | Kritik10,0 | — | %5,7 | 1 Mar 2005 |
42Planlayın | CVE-2004-0418İstismar yok | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attcvs · cvs | Kritik10,0 | — | %5,7 | 6 Ağu 2004 |
- CVE-2004-060862Bu hafta
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2
KritikCVSS 10,0SilahlaştırılmışEPSS %74nerf arena blast · nerf arena blast6 Ara 2004
- CVE-2002-133762Bu hafta
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
KritikCVSS 10,0Kavram kanıtıEPSS %73sendmail · sendmail7 Mar 2003
- CVE-2024-1208461Bu hafta
Rsync: heap buffer overflow in rsync due to improper checksum length handling
KritikCVSS 9,8Kavram kanıtıEPSS %72samba · rsync15 Oca 2025
- CVE-2003-069460Bu hafta
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
KritikCVSS 10,0SilahlaştırılmışEPSS %66sendmail · advanced message server6 Eki 2003
- CVE-2004-103759Planlayın
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
KritikCVSS 10,0SilahlaştırılmışEPSS %62twiki · twiki1 Mar 2005
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %94ssh · ssh18 Ara 2023
- CVE-2004-049350Planlayın
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and p
OrtaCVSS 6,4Kavram kanıtıEPSS %85apache · http server6 Ağu 2004
- CVE-2004-093249Planlayın
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attac
YüksekCVSS 7,5Kavram kanıtıEPSS %64ca · etrust antivirus27 Oca 2005
- CVE-2004-099048Planlayın
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of ser
KritikCVSS 10,0Kavram kanıtıEPSS %28gd graphics library · gdlib1 Mar 2005
- CVE-2004-038648Planlayın
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a l
KritikCVSS 10,0Kavram kanıtıEPSS %27mplayer · mplayer4 May 2004
- CVE-2004-055748Planlayın
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers t
KritikCVSS 10,0Kavram kanıtıEPSS %25sox · sox6 Ağu 2004
- CVE-2004-033347Planlayın
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers
KritikCVSS 10,0Kavram kanıtıEPSS %24uudeview · uudeview23 Kas 2004
- CVE-2007-219446Planlayın
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a l
KritikCVSS 10,0Kavram kanıtıEPSS %19gentoo · xnview24 Nis 2007
- CVE-2012-298245Planlayın
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a path
OrtaCVSS 6,5SilahlaştırılmışEPSS %62gentoo · webmin11 Eyl 2012
- CVE-2004-041644Planlayın
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
KritikCVSS 10,0Kavram kanıtıEPSS %13cvs · cvs6 Ağu 2004
- CVE-2004-130443Planlayın
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF
KritikCVSS 10,0Kavram kanıtıEPSS %11file · file10 Oca 2005
- CVE-2004-088843Planlayın
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
KritikCVSS 10,0İstismar yokEPSS %10kde · koffice27 Oca 2005
- CVE-2004-091443Planlayın
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2)
KritikCVSS 10,0İstismar yokEPSS %9lesstif · lesstif10 Oca 2005
- CVE-2004-102942Planlayın
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly rest
KritikCVSS 9,3Kavram kanıtıEPSS %17sun · jdk1 Mar 2005
- CVE-2004-094742Planlayın
Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.
KritikCVSS 10,0İstismar yokEPSS %7arj software inc. · unarj9 Şub 2005
- CVE-2004-089142Planlayın
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash)
KritikCVSS 10,0İstismar yokEPSS %7rob flynn · gaim27 Oca 2005
- CVE-2004-088942Planlayın
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
KritikCVSS 10,0İstismar yokEPSS %6xpdf · xpdf27 Oca 2005
- CVE-2004-098142Planlayın
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain imag
KritikCVSS 10,0İstismar yokEPSS %6imagemagick · imagemagick9 Şub 2005
- CVE-2004-103442Planlayın
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to
KritikCVSS 10,0İstismar yokEPSS %6kaffeine · kaffeine player1 Mar 2005
- CVE-2004-041842Planlayın
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att
KritikCVSS 10,0İstismar yokEPSS %6cvs · cvs6 Ağu 2004