Vulnerabilities > GNU

DATE CVE VULNERABILITY TITLE RISK
2005-05-26 CVE-2005-1520 Buffer Overflow vulnerability in GNU Mailutils 0.5/0.6
Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-mail.
network
low complexity
gnu
7.5
2005-05-24 CVE-2005-1705 Unspecified vulnerability in GNU GDB
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
local
low complexity
gnu
7.2
2005-05-24 CVE-2005-1704 Numeric Errors vulnerability in GNU GDB
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.
local
low complexity
gnu CWE-189
4.6
2005-05-13 CVE-2005-0758 zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
local
low complexity
gnu canonical
4.6
2005-05-03 CVE-2005-1431 Denial of Service vulnerability in GNUTLS Padding
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.
network
low complexity
gnu
5.0
2005-05-02 CVE-2005-1229 Directory Traversal vulnerability in CPIO Filename
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a ..
local
low complexity
gnu
4.6
2005-05-02 CVE-2005-1228 Multiple Security vulnerability in Apple Mac OS X
Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a ..
network
low complexity
gnu
5.0
2005-05-02 CVE-2005-1111 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
local
high complexity
gnu debian canonical CWE-367
4.7
2005-05-02 CVE-2005-1039 Local Race Condition vulnerability in GNU Coreutils 5.2.1
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.
local
high complexity
gnu
3.7
2005-05-02 CVE-2005-0990 Local Insecure Temporary File Creation vulnerability in GNU Sharutils 4.2.1
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
local
low complexity
gnu
2.1