Vulnerabilities > Gentoo

DATE CVE VULNERABILITY TITLE RISK
2005-01-10 CVE-2004-1025 XPM Image Decoding Buffer Overflow vulnerability in IMLib
Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
network
low complexity
enlightenment gentoo redhat
critical
10.0
2005-01-10 CVE-2004-0996 main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
local
low complexity
cscope debian gentoo sco
2.1
2005-01-10 CVE-2004-0914 Multiple Unspecified vulnerability in LibXPM
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file.
network
low complexity
lesstif x-org xfree86-project gentoo redhat suse
critical
10.0
2004-12-31 CVE-2004-1901 Link Following vulnerability in Gentoo Linux and Portage
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.
local
low complexity
gentoo CWE-59
5.5
2004-12-31 CVE-2004-1491 Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.
network
low complexity
opera gentoo kde suse
5.0
2004-12-31 CVE-2004-1471 Multiple vulnerability in CVS
Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line.
network
high complexity
cvs openpkg sgi freebsd gentoo openbsd
7.1
2004-12-31 CVE-2004-1452 Unspecified vulnerability in Gentoo Linux
Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.
local
low complexity
gentoo
7.2
2004-12-23 CVE-2004-1336 The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
local
low complexity
debian gentoo
2.1
2004-12-23 CVE-2004-0749 Information Disclosure vulnerability in Subversion Mod_Authz_Svn Metadata
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.
network
low complexity
subversion gentoo
5.0
2004-12-21 CVE-2004-1307 Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow. 7.5