Vulnerabilities > GNU > Findutils

DATE CVE VULNERABILITY TITLE RISK
2007-06-04 CVE-2007-2452 Local Buffer Overflow vulnerability in GNU Locate Old Format Locate Database
Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.
network
gnu
6.0
2001-08-31 CVE-2001-1036 GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
local
low complexity
gnu slackware
7.2