Vulnerabilities (CVE)

Filtered by vendor Gnu Subscribe
Total 1100 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1036 2 Gnu, Slackware 2 Findutils, Slackware Linux 2025-04-03 7.2 HIGH N/A
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
CVE-2000-0335 2 Gnu, Isc 2 Glibc, Bind 2025-04-03 7.5 HIGH N/A
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
CVE-2003-0849 1 Gnu 1 Cfengine 2025-04-03 7.5 HIGH N/A
Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.
CVE-2001-1267 1 Gnu 1 Tar 2025-04-03 2.1 LOW N/A
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
CVE-1999-0150 1 Gnu 1 Fingerd 2025-04-03 7.5 HIGH N/A
The Perl fingerd program allows arbitrary command execution from remote users.
CVE-2000-0959 1 Gnu 1 Glibc 2025-04-03 1.2 LOW N/A
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
CVE-2004-1773 1 Gnu 1 Sharutils 2025-04-03 7.5 HIGH N/A
Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
CVE-2002-1216 1 Gnu 1 Tar 2025-04-03 5.0 MEDIUM N/A
GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.
CVE-2004-1185 1 Gnu 1 Enscript 2025-04-03 7.5 HIGH N/A
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
CVE-2006-4624 1 Gnu 1 Mailman 2025-04-03 2.6 LOW N/A
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.
CVE-2005-0990 1 Gnu 1 Sharutils 2025-04-03 2.1 LOW N/A
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
CVE-2002-1344 2 Gnu, Sun 2 Wget, Cobalt Raq Xtr 2025-04-03 5.0 MEDIUM N/A
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
CVE-2005-3424 1 Gnu 1 Gnump3d 2025-04-03 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.
CVE-2004-0256 1 Gnu 1 Libtool 2025-04-03 2.1 LOW N/A
GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.
CVE-2001-1228 1 Gnu 1 Gzip 2025-04-03 7.5 HIGH N/A
Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.
CVE-2002-2099 1 Gnu 1 Data Display Debugger 2025-04-03 7.2 HIGH N/A
Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE.
CVE-2002-0389 1 Gnu 1 Mailman 2025-04-03 2.1 LOW N/A
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
CVE-2000-0270 1 Gnu 1 Emacs 2025-04-03 3.6 LOW N/A
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
CVE-2002-0003 1 Gnu 1 Groff 2025-04-03 7.5 HIGH N/A
Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system.
CVE-1999-0491 1 Gnu 1 Bash 2025-04-03 4.6 MEDIUM N/A
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.