← Back

Gentoo

gentoo

178 CVEs • 30 products

Products (30)

Click to collapse
Toggle
Linux
linux
Portage
portage
Logrotate
logrotate
Webmin
webmin
Xnview
xnview
Xdg Utils
xdg-utils
Cman
cman
Fence
fence
Soko
soko
Syslinux
syslinux
Mirrorselect
mirrorselect
Rootkit Hunter
rootkit_hunter
Poppassd Pam
poppassd_pam
Linux Eix
linux_eix
Qt Unixodbc
qt-unixodbc
Nview
nview
File
file
Glibc
glibc
Nvclock
nvclock
Php Toolkit
php_toolkit
Nullmailer
nullmailer
Security
security
Gentoo Linux
gentoo_linux

CVEs (178)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Gentoo
Mediawiki
2Linux
Mediawiki
Apr 29, 2026
Nov 18, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is...Show more
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is then incorrectly interpreted as UTF-8 by Chrome and Firefox.Show less
2Aircrack Ng
Gentoo
2Aircrack Ng
Linux
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL pack...Show more
Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL packet.Show less
1Gentoo
1Webmin
Apr 29, 2026
Sep 11, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in file/show.cgi in Webmin 1.590 and earlier allow remote attackers to hijack the authentication of privileged users for requests that (1) read files or execute (2) tar, (3) zip, or (4) gzip commands, a different issue than CVE-2012-2982.Show less
1Gentoo
1Webmin
Apr 29, 2026
Sep 11, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file field.
1Gentoo
1Webmin
Apr 29, 2026
Sep 11, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
1Gentoo
1Webmin
Apr 29, 2026
Sep 11, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
1Gentoo
1Logrotate
Apr 29, 2026
Mar 30, 2011
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by...Show more
The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories for the (1) cobbler, (2) inn, (3) safte-monitor, and (4) uucp packages.Show less
1Gentoo
1Logrotate
Apr 29, 2026
Mar 30, 2011
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveragi...Show more
The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by directories under /var/log/ for packages.Show less
1Gentoo
1Logrotate
Apr 29, 2026
Mar 30, 2011
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leve...Show more
The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to conduct symlink and hard link attacks by leveraging logrotate's lack of support for untrusted directories, as demonstrated by /var/log/postgresql/.Show less
1Gentoo
1Logrotate
Apr 29, 2026
Mar 30, 2011
N/A· v4
N/A· v3
1.9 LOW· v2
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log...Show more
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.Show less
1Gentoo
1Logrotate
Apr 29, 2026
Mar 30, 2011
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that i...Show more
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.Show less
1Gentoo
1Logrotate
Apr 29, 2026
Mar 30, 2011
N/A· v4
N/A· v3
1.9 LOW· v2
Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
1Gentoo
2Cman
Fence
Apr 23, 2026
Oct 15, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.
1Gentoo
2Cman
Fence
Apr 23, 2026
Oct 15, 2008
N/A· v4
N/A· v3
1.9 LOW· v2
The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog t...Show more
The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.Show less
1Gentoo
1Portage
Apr 23, 2026
Oct 10, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module th...Show more
Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.Show less
1Gentoo
1Php Toolkit
Apr 23, 2026
Apr 18, 2008
N/A· v4
N/A· v3
3.6 LOW· v2
Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphab...Show more
Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.Show less
1Gentoo
1Linux
Apr 23, 2026
Mar 18, 2008
N/A· v4
N/A· v3
1.9 LOW· v2
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems th...Show more
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.Show less
2Gentoo
Rpath
2Linux
Rpath Linux
Apr 23, 2026
Feb 29, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same iss...Show more
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.Show less
1Gentoo
1Xdg Utils
Apr 23, 2026
Feb 4, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.
1Gentoo
1Portage
Apr 23, 2026
Dec 15, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to ob...Show more
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.Show less