Vulnerabilities (CVE)

Filtered by vendor Gnu Subscribe
Total 1196 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0150 1 Gnu 1 Fingerd 2026-04-16 7.5 HIGH N/A
The Perl fingerd program allows arbitrary command execution from remote users.
CVE-2000-0959 1 Gnu 1 Glibc 2026-04-16 1.2 LOW N/A
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
CVE-2004-1773 1 Gnu 1 Sharutils 2026-04-16 7.5 HIGH N/A
Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
CVE-2002-1216 1 Gnu 1 Tar 2026-04-16 5.0 MEDIUM N/A
GNU tar 1.13.19 and other versions before 1.13.25 allows remote attackers to overwrite arbitrary files via a symlink attack, as the result of a modification that effectively disabled the security check.
CVE-2004-1185 1 Gnu 1 Enscript 2026-04-16 7.5 HIGH N/A
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
CVE-2006-4624 1 Gnu 1 Mailman 2026-04-16 2.6 LOW N/A
CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting malicious URLs via CRLF sequences in the URI.
CVE-2005-0990 1 Gnu 1 Sharutils 2026-04-16 2.1 LOW N/A
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
CVE-2002-1344 2 Gnu, Sun 2 Wget, Cobalt Raq Xtr 2026-04-16 5.0 MEDIUM N/A
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
CVE-2005-3424 1 Gnu 1 Gnump3d 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.
CVE-2004-0256 1 Gnu 1 Libtool 2026-04-16 2.1 LOW N/A
GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.
CVE-2001-1228 1 Gnu 1 Gzip 2026-04-16 7.5 HIGH N/A
Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.
CVE-2002-2099 1 Gnu 1 Data Display Debugger 2026-04-16 7.2 HIGH N/A
Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE.
CVE-2002-0389 1 Gnu 1 Mailman 2026-04-16 2.1 LOW N/A
Pipermail in Mailman stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing list archives.
CVE-2000-0270 1 Gnu 1 Emacs 2026-04-16 3.6 LOW N/A
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
CVE-2002-0003 1 Gnu 1 Groff 2026-04-16 7.5 HIGH N/A
Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system.
CVE-1999-0491 1 Gnu 1 Bash 2026-04-16 4.6 MEDIUM N/A
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
CVE-2003-0858 2 Gnu, Quagga 2 Zebra, Quagga Routing Software Suite 2026-04-16 2.1 LOW N/A
Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
CVE-2004-0131 1 Gnu 1 Radius 2026-04-16 5.0 MEDIUM N/A
The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.
CVE-2006-0455 1 Gnu 1 Privacy Guard 2026-04-16 4.6 MEDIUM N/A
gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command "gpg --verify".
CVE-2004-1177 1 Gnu 1 Mailman 2026-04-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.