Vulnerabilities > Sentex

DATE CVE VULNERABILITY TITLE RISK
2008-10-21 CVE-2008-4641 Improper Input Validation vulnerability in Sentex Jhead
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.
network
low complexity
sentex CWE-20
critical
10.0
2008-10-21 CVE-2008-4640 Improper Input Validation vulnerability in Sentex Jhead
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
local
low complexity
sentex CWE-20
3.6
2008-10-21 CVE-2008-4639 Unspecified vulnerability in Sentex Jhead
jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
local
low complexity
sentex
4.6
2008-10-15 CVE-2008-4575 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Sentex Jhead
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
network
low complexity
sentex CWE-119
5.0