| OSVDB ID | Disclosure Date | Title |
|
11621
Description:
(Description Provided by CVE) : gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.
|
2001-06-26
|
GNATS GnatsWeb gnatsweb.pl Arbitrary Command Execution
|
|
11622
Description:
GNATS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to a format string condition in the logging functions. With a specially formatted request that is passed to $SYSLOG, a remote attacker could execute command with the privilege of the GNATS process.
|
2004-06-25
|
GNATS log_msg() Function Remote Format String
|
|
36224
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter.
|
2007-05-19
|
Gnatsweb gnatsweb.pl database Parameter XSS
|
|
29865
Description:
(Description Provided by CVE) : Format string vulnerability in the flush_output function in ConsoleStreambuf.cpp in Game Network Engine (GNE) 0.70 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute code via format string specifiers in unspecified vectors involving output to the gout console.
|
2006-07-24
|
GNE ConsoleStreambuf.cpp flush_output Function Remote Format String
|
|
50780
Description:
Gnews Publisher contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the authors.asp script not properly sanitizing user-supplied input to the authorID parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-12-16
|
gNews Publisher authors.asp authorID Parameter SQL Injection
|
|
31919
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in categories.asp in gNews Publisher allow remote attackers to execute arbitrary SQL commands via the (1) catID or (2) editorID parameter.
|
2006-11-20
|
gNews Publisher categories.asp Multiple Parameter SQL Injection
|
|
6684
Description:
An overflow exists in Gnocatan. Gnocatan fails to check boundary, resulting in a buffer overflow. With a specially crafted request, an attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service, resulting in a loss of integrity.
|
2003-06-11
|
gnocatan Multiple Unspecified Overflows
|
|
10853
Description:
Gnofract 4d contains a flaw related to a .fct file that may allow an attacker to insert and execute arbitrary Python code. No further details have been provided.
|
2004-10-16
|
Gnofract 4D .fct File Arbitrary Python Code Execution
|
|
6553
Description:
A remote overflow exists in Gnome Batalla Naval gbnserver. The issue is due to a boundary error in gbnserver. By sending an overly long string, an attacker can cause a buffer overflow and crash the server or execute arbitrary code with game server user privileges, resulting in a loss of integrity.
|
2003-05-26
|
Gnome Batalla Naval gbnserver Remote Overflow
|
|
31771
Description:
(Description Provided by CVE) : Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used.
|
2006-06-01
|
GNOME Crafted Header camel-internet-address.c Null Pointer DoS
|
|
72551
Description:
(Description Provided by CVE) : GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.
|
2011-03-28
|
GNOME Display Manager (gdm) /var/cache/gdm/ Multiple File Symlink Local Privilege Escalation
|
|
26269
Description:
(Description Provided by CVE) : GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges.
|
2006-06-08
|
GNOME Display Manager (gdm) Configure Login Manager Authentication Privilege Escalation
|
|
66643
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
|
2009-02-15
|
GNOME Display Manager (gdm) Debug Mode /var/log/messages Password Disclosure
|
|
39560
Description:
(Description Provided by CVE) : The GDM daemon in GNOME Display Manager (GDM) before 2.14.13, 2.16.x before 2.16.7, 2.18.x before 2.18.4, and 2.19.x before 2.19.5 does not properly handle NULL return values from the g_strsplit function, which allows local users to cause a denial of service (persistent daemon crash) via a crafted command to the daemon's socket, related to (1) gdm.c and (2) gdmconfig.c in daemon/, and (3) gdmconfig.c and (4) gdmflexiserver.c in gui/.
|
2007-07-30
|
GNOME Display Manager (gdm) g_strsplit Function Local DoS
|
|
30848
Description:
Gnome Display Manager contains a flaw that may allow a malicious user to to gain escalated privileges. The issue is is caused due to a format string error within the 'gdm_chooser_add_host()' function in gdm2/gui/gdmchooser.c. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2006-12-14
|
GNOME Display Manager (gdm) gdmchooser hostname Format String
|
|
73035
Description:
(Description Provided by CVE) : GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows local users to gain privileges via vectors involving the x-scheme-handler/http MIME type.
|
2011-05-30
|
GNOME Display Manager (gdm) glib2 Web Browser x-scheme-handler/http MIME Type Local Privilege Escalation
|
|
57657
Description:
(Description Provided by CVE) : The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.
|
2009-09-02
|
GNOME Display Manager (gdm) on Red Hat Linux TCP Wrapper Support Weakness
|
|
72550
Description:
Unknown / Incomplete
|
2010-01-21
|
GNOME Display Manager (gdm) PostLogin Script User Assignment Weakness
|
|
1547
Description:
(Description Provided by CVE) : Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack.
|
2000-09-11
|
GNOME esound Symlink Privilege Escalation
|
|
18690
Description:
(Description Provided by CVE) : Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.
|
2005-08-10
|
GNOME Evolution Calendar Tab Task List Data Format String
|
|
13160
Description:
A remote overflow exists in Evolution. Evolution contains a flaw in the camel-lock-helper application resulting in an integer overflow. With a specially crafted request, a malicious, local user or POP3 server can execute arbitrary code with the privileges of the camel-lock-helper application resulting in a loss of integrity.
|
2005-01-25
|
GNOME Evolution camel-lock-helper Overflow
|
|
23586
Description:
(Description Provided by CVE) : GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.
|
2006-03-02
|
GNOME Evolution Crafted HTML Email DoS
|
|
12648
Description:
(Description Provided by CVE) : GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.
|
2003-03-13
|
GNOME Evolution GtkHTML Malformed Mail Message DoS
|
|
18688
Description:
Evolution contains a flaw that may allow a malicious user to execute arbitrary code. The issue is related to an unspecified format string flaw in the display of LDAP contact data. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2005-08-10
|
GNOME Evolution LDAP Server Contact Data Remote Format String
|
|
22923
Description:
(Description Provided by CVE) : The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.
|
2006-01-30
|
GNOME Evolution Mail Client Inline Text File Content-Disposition DoS
|
|
18689
Description:
Evolution contains a flaw that may allow a malicious user to execute arbitrary code. The issue is due to an unspecified format string flaw related to the display of task list data from remote servers. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2005-08-10
|
GNOME Evolution Task List Data Remote Format String
|
|
18687
Description:
(Description Provided by CVE) : Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.
|
2005-08-10
|
GNOME Evolution vCard Attachment Format String
|
|
16809
Description:
gedit contains a flaw that may allow a local denial of service. The issue is triggered due to the handling of binary files with format string specifiers in the filename. With a specially crafted filename, a malicious user can cause the application to crash resulting in a loss of availability.
|
2005-05-20
|
GNOME gedit Filename Format String DoS
|
|
4667
Description:
Unknown / Incomplete
|
2004-03-30
|
GNOME gnome-session LD_LIBRARY_PATH Privilege Escalation
|
|
18693
Description:
(Description Provided by CVE) : xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
|
2005-08-10
|
GNOME gpdf Temporary File Disk Space Consumption DoS
|