Vulnerabilities > Gentoo > Critical

DATE CVE VULNERABILITY TITLE RISK
2005-01-27 CVE-2004-0888 Integer Overflow vulnerability in Xpdf PDFTOPS
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
10.0
2005-01-10 CVE-2004-1304 Buffer Overflow vulnerability in File ELF Header
Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.
network
low complexity
file gentoo trustix
critical
10.0
2005-01-10 CVE-2004-1026 XPM Image Decoding Buffer Overflow vulnerability in IMLib
Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
network
low complexity
enlightenment gentoo redhat
critical
10.0
2005-01-10 CVE-2004-1025 XPM Image Decoding Buffer Overflow vulnerability in IMLib
Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
network
low complexity
enlightenment gentoo redhat
critical
10.0
2005-01-10 CVE-2004-0914 Multiple Unspecified vulnerability in LibXPM
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file.
network
low complexity
lesstif x-org xfree86-project gentoo redhat suse
critical
10.0
2004-12-06 CVE-2004-0608 The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory. 10.0
2004-11-23 CVE-2004-0333 Buffer Overrun vulnerability in UUDeview MIME Archive
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.
network
low complexity
openpkg uudeview winzip gentoo
critical
10.0
2004-08-18 CVE-2004-0226 Multiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
midnight-commander sgi gentoo slackware
critical
10.0
2004-08-06 CVE-2004-0649 Buffer overflow in write_packet in control.c for l2tpd may allow remote attackers to execute arbitrary code.
network
low complexity
l2tpd gentoo
critical
10.0
2004-08-06 CVE-2004-0557 Buffer Overflow vulnerability in SoX WAV File
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.
network
low complexity
sox conectiva gentoo redhat
critical
10.0