← Back

Root

root

Vendor: Root • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Root
1Root
Feb 19, 2026
Jan 27, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.
1Root
1Root
Apr 29, 2026
Oct 20, 2010
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The (1) proofserv, (2) xrdcp, (3) xrdpwdadmin, and (4) xrd scripts in ROOT 5.18/00 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library...Show more
The (1) proofserv, (2) xrdcp, (3) xrdpwdadmin, and (4) xrd scripts in ROOT 5.18/00 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.Show less