Gentoo
Gentoo Linux: vulnerabilidades y CVE
Gentoo Linux tiene 136 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE136
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-12084 | Crítica (9.8) | 72% | — | 15 ene 2025 | A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH… |
| CVE-2024-12088 | Alta (7.5) | 4.7% | — | 14 ene 2025 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a… |
| CVE-2024-12087 | Alta (7.5) | 2.3% | — | 14 ene 2025 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly… |
| CVE-2024-12086 | Media (6.8) | 1.8% | — | 14 ene 2025 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process,… |
| CVE-2024-12085 | Alta (7.5) | 8.8% | — | 14 ene 2025 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized… |
| CVE-2014-4909 | Media (6.8) | 5.4% | — | 29 jul 2014 | Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer… |
| CVE-2013-0348 | Baja (2.1) | 0.52% | — | 13 dic 2013 | thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file. |
| CVE-2013-2032 | Media (5) | 2.5% | — | 18 nov 2013 | MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the… |
| CVE-2013-2031 | Media (4.3) | 2.5% | — | 18 nov 2013 | MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is… |
| CVE-2010-1159 | Media (6.8) | 7.3% | — | 28 oct 2013 | Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL… |
| CVE-2008-1383 | Baja (1.9) | 0.21% | — | 18 mar 2008 | The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems… |
| CVE-2008-1078 | Alta (7.2) | 0.51% | — | 29 feb 2008 | expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same… |
| CVE-2007-1500 | Media (4.3) | 0.32% | — | 19 mar 2007 | The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat. |
| CVE-2007-0476 | Media (4.6) | 0.36% | — | 25 ene 2007 | The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge,… |
| CVE-2006-3005 | Media (5) | 1.9% | — | 13 jun 2006 | The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG… |
| CVE-2006-1390 | Media (4.6) | 0.73% | — | 25 mar 2006 | The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary… |
| CVE-2006-0071 | Media (6.6) | 0.39% | — | 4 ene 2006 | The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0. |
| CVE-2005-3625 | Alta (10) | 3.8% | — | 31 dic 2005 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated… |
| CVE-2005-3626 | Media (5) | 3.4% | — | 31 dic 2005 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null… |
| CVE-2005-3624 | Media (5) | 2.3% | — | 31 dic 2005 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a… |
| CVE-2005-2557 | Media (4.3) | 2.6% | — | 28 sept 2005 | Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a… |
| CVE-2005-1267 | Media (5) | 14% | — | 10 jun 2005 | The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP… |
| CVE-2005-0988 | Baja (3.7) | 0.66% | — | 2 may 2005 | Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose… |
| CVE-2005-0077 | Baja (2.1) | 0.41% | — | 2 may 2005 | The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file. |
| CVE-2005-1121 | Media (5) | 2.3% | — | 2 may 2005 | Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute… |
| CVE-2005-0005 | Alta (7.5) | 4.4% | — | 2 may 2005 | Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers. |
| CVE-2005-0206 | Alta (7.5) | 3.0% | — | 27 abr 2005 | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the… |
| CVE-2005-0754 | Alta (7.5) | 3.0% | — | 22 abr 2005 | Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code. |
| CVE-2004-1176 | Alta (7.5) | 3.1% | — | 14 abr 2005 | Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. |
| CVE-2004-1175 | Alta (7.5) | 1.6% | — | 14 abr 2005 | fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters. |