Vulnerabilities > Gentoo > Linux

DATE CVE VULNERABILITY TITLE RISK
2005-04-14 CVE-2004-1005 Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. 7.5
2005-04-14 CVE-2004-1004 Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. 7.5
2005-03-14 CVE-2005-0470 Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.
network
low complexity
wpa-supplicant gentoo suse
5.0
2005-03-07 CVE-2005-0667 Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.
network
high complexity
sylpheed sylpheed-claws altlinux gentoo redhat
5.1
2005-03-01 CVE-2004-1055 Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.
network
phpmyadmin gentoo
6.8
2005-03-01 CVE-2004-1052 Buffer Overflow vulnerability in BNC getnickuserhost IRC Server Response
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.
network
low complexity
bnc debian gentoo
critical
10.0
2005-03-01 CVE-2004-1037 Remote Arbitrary Command Execution vulnerability in TWiki Search Shell Metacharacter
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
network
low complexity
twiki gentoo
critical
10.0
2005-03-01 CVE-2004-1036 Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML. 6.8
2005-03-01 CVE-2004-1034 Remote Buffer Overflow vulnerability in Kaffeine
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.
network
low complexity
kaffeine xine gentoo
critical
10.0
2005-03-01 CVE-2004-1033 Local vulnerability in Fcron FCronTab/FCronSighUp
Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.
local
low complexity
thibault-godouet gentoo
2.1