Search: "gnu"

1221 CVEs found

CVE-2000-1136
4.6 MEDIUM

elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.

Published: 2001-01-09
Products: 1
Vendors:
debian
CVE-2000-1137
4.6 MEDIUM

GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.

Published: 2001-01-09
Products: 4
Vendors:
gnu

dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.

Published: 2001-02-12
Products: 6
Vendors:
debian

gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.

Published: 2001-02-12
Products: 5
Vendors:
gnu
CVE-2001-0072
5.0 MEDIUM

gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web ...

Published: 2001-02-12
Products: 5
Vendors:
gnu

sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.

Published: 2001-03-26
Products: 1
Vendors:
debian
CVE-2001-0191
10.0 HIGH

gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buf...

Published: 2001-05-03
Products: 2
Vendors:
gnu andynorman

pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in clea...

Published: 2001-05-03
Products: 1
Vendors:
holger_lamm

Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).

Published: 2001-07-12
Products: 1
Vendors:
gnu

Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted...

Published: 2001-08-14
Products: 3
Vendors:
gnu
CVE-2001-1004
5.0 MEDIUM

Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tag...

Published: 2001-08-31
Products: 1
Vendors:
gnutella

GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which c...

Published: 2001-08-31
Products: 4
Vendors:
slackware gnu

Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a long SITE command.

Published: 2001-10-18
Products: 1
Vendors:
debian

GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.

Published: 2002-01-31
Products: 8
Vendors:
redhat debian gnu
CVE-2002-1602
4.6 MEDIUM

Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.

Published: 2002-04-23
Products: 5
Vendors:
gnu

Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to ex...

Published: 2002-05-16
Products: 1
Vendors:
gnu

Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.

Published: 2002-05-29
Products: 3
Vendors:
ada_core_technologies
CVE-2002-0300
5.0 MEDIUM

gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass access restrictions by directly requesting the target file from the gnujsp servlet, ...

Published: 2002-05-31
Products: 2
Vendors:
gnujsp

Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils b...

Published: 2002-07-26
Products: 3
Vendors:
gnu

Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arb...

Published: 2002-08-12
Products: 2
Vendors:
greg_roelofs