← Back

Rpath

rpath

13 CVEs • 6 products

Products (6)

Click to collapse
Toggle

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rpath
1Initscripts
Apr 23, 2026
Nov 17, 2008
N/A· v4
N/A· v3
6.9 MEDIUM· v2
rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. NOTE: this issue exists because of a rac...Show more
rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. NOTE: this issue exists because of a race condition in an incorrect fix for CVE-2008-3524. NOTE: exploitation may require an unusual scenario in which rc.sysinit is executed other than at boot time.Show less
2Rpath
Wireshark
2Rpath Linux
Wireshark
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: this might be due to a use-after-free error.
2Rpath
Wireshark
2Rpath Linux
Wireshark
Apr 23, 2026
Jul 10, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vectors.
3Foresight Linux
RedhatRpath
4Appliance Platform Agent
AppliancesEnterprise Linux+1 more
Apr 23, 2026
May 22, 2008
N/A· v4
N/A· v3
7.1 HIGH· v2
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of servi...Show more
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.Show less
1Rpath
1Appliance Platform Agent
Apr 23, 2026
May 12, 2008
N/A· v4
N/A· v3
2.6 LOW· v2
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.
1Rpath
1Appliance Platform Agent
Apr 23, 2026
May 12, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically...Show more
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.Show less
2Gentoo
Rpath
2Linux
Rpath Linux
Apr 23, 2026
Feb 29, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same iss...Show more
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.Show less
1Rpath
1Rpath Linux
Apr 23, 2026
Oct 28, 2007
N/A· v4
N/A· v3
4.9 MEDIUM· v2
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure perm...Show more
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.Show less
1Rpath
1Rmake
Apr 23, 2026
Oct 4, 2007
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as /dev/port, which might allow local users to gain root privileges.
8Mandrakesoft
OpenbsdRedhat+5 more
12Enterprise Linux
Enterprise Linux DesktopFedora Core+9 more
Apr 23, 2026
Apr 6, 2007
N/A· v4
N/A· v3
3.8 LOW· v2
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overfl...Show more
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.Show less
7Mandrakesoft
OpenbsdRedhat+4 more
9Enterprise Linux
Enterprise Linux DesktopLibxfont+6 more
Apr 23, 2026
Apr 6, 2007
N/A· v4
N/A· v3
8.5 HIGH· v2
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts,...Show more
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.Show less
1Rpath
1Rpath Linux
Apr 23, 2026
Jan 27, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges.
6Gnu
Gpg4winRedhat+3 more
9Enterprise Linux
Enterprise Linux DesktopFedora Core+6 more
Apr 23, 2026
Dec 7, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a funct...Show more
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.Show less