CVE-2008-1078
- EPSS 0.03%
- Published 29.02.2008 02:44:00
- Last modified 09.04.2025 00:30:58
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.
CVE-2007-1500
- EPSS 0.06%
- Published 19.03.2007 22:19:00
- Last modified 09.04.2025 00:30:58
The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.
CVE-2007-0476
- EPSS 0.07%
- Published 25.01.2007 00:28:00
- Last modified 09.04.2025 00:30:58
The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to over...
- EPSS 0.54%
- Published 13.06.2006 10:02:00
- Last modified 03.04.2025 01:03:51
The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended me...
CVE-2006-1390
- EPSS 0.22%
- Published 25.03.2006 00:06:00
- Last modified 03.04.2025 01:03:51
The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and ...
CVE-2006-0071
- EPSS 0.05%
- Published 04.01.2006 00:03:00
- Last modified 03.04.2025 01:03:51
The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.
- EPSS 7.36%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to int...
- EPSS 11.29%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...
- EPSS 9.33%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
CVE-2005-2557
- EPSS 8.43%
- Published 28.09.2005 21:03:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE...