← Back

Gentoo

gentoo

178 CVEs • 30 products

Products (30)

Click to collapse
Toggle
Linux
linux
Portage
portage
Logrotate
logrotate
Webmin
webmin
Xnview
xnview
Xdg Utils
xdg-utils
Cman
cman
Fence
fence
Soko
soko
Syslinux
syslinux
Mirrorselect
mirrorselect
Rootkit Hunter
rootkit_hunter
Poppassd Pam
poppassd_pam
Linux Eix
linux_eix
Qt Unixodbc
qt-unixodbc
Nview
nview
File
file
Glibc
glibc
Nvclock
nvclock
Php Toolkit
php_toolkit
Nullmailer
nullmailer
Security
security
Gentoo Linux
gentoo_linux

CVEs (178)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gentoo
1Mldonkey Ebuild
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.
1Gentoo
1Nvclock
Apr 23, 2026
Jul 25, 2007
N/A· v4
N/A· v3
6.6 MEDIUM· v2
The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file.
1Gentoo
1Glibc
Apr 23, 2026
Jul 3, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers...Show more
Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code executionShow less
1Gentoo
1Xnview
Apr 23, 2026
Apr 24, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party i...Show more
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.Show less
2Amavis
Gentoo
2File
Virus Scanner
Apr 23, 2026
Apr 13, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled...Show more
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.Show less
1Gentoo
1Linux
Apr 23, 2026
Mar 19, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.
1Gentoo
1Linux
Apr 23, 2026
Jan 25, 2007
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, wh...Show more
The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.Show less
1Gentoo
2Linux
Media Libs Jpeg
Apr 16, 2026
Jun 13, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG fil...Show more
The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.Show less
1Gentoo
1Linux
Apr 16, 2026
Mar 25, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary...Show more
The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.Show less
1Gentoo
2App Crypt Pinentry
Linux
Apr 16, 2026
Jan 4, 2006
N/A· v4
N/A· v3
6.6 MEDIUM· v2
The ebuild for pinentry before 0.7.2-r2 on Gentoo Linux sets setgid bits for pinentry programs, which allows local users to read or overwrite arbitrary files as gid 0.
1Gentoo
2Nview
Xnview
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Untrusted search path vulnerability (RPATH) in XnView 1.70 and NView 4.51 on Gentoo Linux allows local users to execute arbitrary code via a malicious library in the current working directory.
18Conectiva
DebianEasy Software Products+15 more
33Cups
Debian LinuxEnterprise Linux+30 more
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null derefer...Show more
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.Show less
18Conectiva
DebianEasy Software Products+15 more
33Cups
Debian LinuxEnterprise Linux+30 more
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated usi...Show more
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."Show less
18Conectiva
DebianEasy Software Products+15 more
33Cups
Debian LinuxEnterprise Linux+30 more
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDe...Show more
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.Show less
1Gentoo
1Qt Unixodbc
Apr 16, 2026
Dec 16, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which...Show more
Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.Show less
1Gentoo
1Linux Eix
Apr 16, 2026
Nov 23, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the d...Show more
Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the diff-eix program.Show less
3Debian
GentooMantis
3Debian Linux
LinuxMantis
Apr 16, 2026
Sep 28, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a di...Show more
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.Show less
5Gentoo
LblMandrakesoft+2 more
5Fedora Core
LinuxMandrake Linux+2 more
Apr 16, 2026
Jun 10, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packe...Show more
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.Show less
1Gentoo
1Linux Webapp Config
Apr 16, 2026
May 24, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.
2Gentoo
Igor Khasilev
2Linux
Oops Proxy Server
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitra...Show more
Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.Show less