Show filters
173 Total Results
Displaying 31-40 of 173
Sort by:
Attacker Value
Unknown
CVE-2008-1734
Disclosure Date: April 18, 2008 (last updated October 04, 2023)
Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
0
Attacker Value
Unknown
CVE-2008-1383
Disclosure Date: March 18, 2008 (last updated October 04, 2023)
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.
0
Attacker Value
Unknown
CVE-2008-1078
Disclosure Date: February 29, 2008 (last updated November 08, 2023)
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.
0
Attacker Value
Unknown
CVE-2008-0386
Disclosure Date: February 04, 2008 (last updated October 04, 2023)
Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.
0
Attacker Value
Unknown
CVE-2007-6249
Disclosure Date: December 15, 2007 (last updated October 04, 2023)
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.
0
Attacker Value
Unknown
CVE-2007-5714
Disclosure Date: October 30, 2007 (last updated October 04, 2023)
The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2007-3531
Disclosure Date: July 25, 2007 (last updated October 04, 2023)
The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file.
0
Attacker Value
Unknown
CVE-2007-3508
Disclosure Date: July 03, 2007 (last updated November 08, 2023)
Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution
0
Attacker Value
Unknown
CVE-2007-2194
Disclosure Date: April 24, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-2026
Disclosure Date: April 13, 2007 (last updated October 04, 2023)
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
0