← Back

Linux

linux

Vendor: Gentoo • 136 CVEs

CVEs (136)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Gentoo
Phpmyadmin
2Linux
Phpmyadmin
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in r...Show more
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin parser.Show less
3Bnc
DebianGentoo
3Bnc
Debian LinuxLinux
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (a...Show more
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.Show less
2Gentoo
Twiki
2Linux
Twiki
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
2Gentoo
Squirrelmail
2Linux
Squirrelmail
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbi...Show more
Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.Show less
3Gentoo
KaffeineXine
3Gxine
Kaffeine PlayerLinux
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary cod...Show more
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.Show less
2Gentoo
Thibault Godouet
2Fcron
Linux
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.
2Gentoo
Thibault Godouet
2Fcron
Linux
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such...Show more
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.Show less
2Gentoo
Thibault Godouet
2Fcron
Linux
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configur...Show more
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration file by starting an suid process and pointing the fcronsighup configuration file to a /proc entry that is owned by root but modifiable by the user, such as /proc/self/cmdline or /proc/self/environ.Show less
2Gentoo
Thibault Godouet
2Fcron
Linux
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be pars...Show more
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message.Show less
5Conectiva
GentooHp+2 more
8Enterprise Firewall
Gateway Security 5400Hp Ux+5 more
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
9.3 HIGH· v2
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allo...Show more
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.Show less
3Arjsoftware
DebianGentoo
3Debian Linux
LinuxUnarj
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.
5Gd Graphics Library
GentooOpenpkg+2 more
5Gdlib
LinuxOpenpkg+2 more
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image ro...Show more
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.Show less
4Gentoo
MandrakesoftUbuntu+1 more
5Linux
Mandrake LinuxMandrake Linux Corporate Server+2 more
Apr 16, 2026
Mar 1, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.
2Gentoo
Mediawiki
2Linux
Mediawiki
Apr 16, 2026
Feb 22, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.
4Debian
GentooImagemagick+1 more
4Debian Linux
ImagemagickLinux+1 more
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
3Angus Mackay
DebianGentoo
3Debian Linux
Ez IpupdateLinux
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
3Gentoo
MandrakesoftOpenssl
5Linux
Mandrake LinuxMandrake Linux Corporate Server+2 more
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
2Gentoo
Lvm
2Linux
Logical Volume Management Utilities
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
3Gentoo
GnuUbuntu
3Groff
LinuxUbuntu Linux
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on tempor...Show more
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.Show less
3Arj Software Inc.
GentooSuse
3Linux
Suse LinuxUnarj
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.