| OSVDB ID | Disclosure Date | Title |
|
52158
Description:
(Description Provided by CVE) : Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename.
|
2008-12-15
|
GNU Enscript src/psgen.c epsf Escape Sequence Overflow
|
|
52159
Description:
(Description Provided by CVE) : Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename.
|
2008-12-15
|
GNU Enscript src/util.c epsf Escape Sequence Overflow
|
|
13154
Description:
(Description Provided by CVE) : The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
|
2005-01-21
|
GNU Enscript EPSF Pipe Support Arbitrary Command Execution
|
|
2030
Description:
(Description Provided by CVE) : GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
|
2002-01-18
|
GNU Enscript Insecure Temporary File Creation
|
|
13155
Description:
GNU Enscript contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when creates specially crafted filenames. It is possible that the flaw may allow the attacker to inject arbitrary code resulting in a loss of integrity.
|
2005-01-21
|
GNU Enscript Malformed Filename Arbitrary Command Execution
|
|
13156
Description:
GNU Escript contains multiple non-descript overflows that may allow an attacker to cause a denial of service condition. No further details have been provided.
|
2005-01-21
|
GNU Enscript Multiple Unspecified Overflows DoS
|
|
49224
Description:
(Description Provided by CVE) : Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.
|
2008-10-22
|
GNU Enscript src/psgen.c read_special_escape() Function Special Escape Overflow
|
|
34995
Description:
(Description Provided by CVE) : The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
|
2007-04-18
|
GNU file Crafted Document Handling Local DoS
|
|
38498
Description:
(Description Provided by CVE) : Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.
|
2007-05-23
|
GNU file File Handling Local Overflow
|
|
5294
Description:
(Description Provided by CVE) : Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.
|
2004-04-08
|
GNU Fileutils Delete Arbitrary Files
|
|
5477
Description:
A local buffer overflow exists in the GNU findutils locate command. The locate command fails to check input in the old locate database format resulting in a potential buffer overflow. With a specially crafted entry in such a database file, an attacker can cause execution of code resulting in a loss of confidentiality and integrity.
|
2001-08-01
|
GNU findutils locate Memory Write Privilege Escalation
|
|
36827
Description:
(Description Provided by CVE) : Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.
|
2007-05-30
|
GNU findutils locate/locate.c visit_old_format Function Overflow
|
|
64
Description:
(Description Provided by CVE) : finger allows recursive searches by using a long string of @ symbols.
|
1992-10-28
|
GNU finger Recursive Request DoS
|
|
10873
Description:
(Description Provided by CVE) : GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
|
1995-03-17
|
GNU fingerd .fingerrc Arbitrary Command Execution Privilege Escalation
|
|
10874
Description:
(Description Provided by CVE) : GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
|
1995-03-17
|
GNU fingerd Symlink Arbitrary Privileged File Access
|
|
19098
Description:
(Description Provided by CVE) : The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.
|
2002-05-06
|
Gnu GCC / g++ -ftrapv Option Integer Overflow Handling Issue
|
|
27380
Description:
(Description Provided by CVE) : Directory traversal vulnerability in FastJar 0.93, as used in Gnu GCC 4.1.1 and earlier, and 3.4.6 and earlier, allows user-assisted attackers to overwrite arbitrary files via a .jar file containing filenames with "../" sequences.
|
2006-07-12
|
Gnu GCC fastjar JAR Processing Traversal Arbitrary File Write
|
|
31432
Description:
(Description Provided by CVE) : fold_binary in fold-const.c in GNU Compiler Collection (gcc) 4.1 improperly handles pointer overflow when folding a certain expr comparison to a corresponding offset comparison in cases other than EQ_EXPR and NE_EXPR, which might introduce buffer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.NOTE: the vendor states that the essence of the issue is "not correctly interpreting an offset to a pointer as a signed value."
|
2006-04-17
|
Gnu GCC fold-const.c fold_binary Function Overflow Weakness
|
|
65446
Description:
Unknown / Incomplete
|
2010-04-27
|
Gnu GCC FORTIFY_SOURCE sgid Application Address Space Local Disclosure
|
|
4783
Description:
Unknown / Incomplete
|
2003-05-22
|
Gnu GCC Implicit struct-copy Privilege Escalation
|
|
44142
Description:
(Description Provided by CVE) : ** DISPUTED ** gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999).
|
2008-03-30
|
Gnu GCC Length Testing Code Failure Code Compilation Weakness
|
|
43548
Description:
(Description Provided by CVE) : gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.
|
2008-03-06
|
Gnu GCC String Manipulation Compiling Functions Data Copying Memory Corruption
|
|
13527
Description:
(Description Provided by CVE) : gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files.
|
1998-01-02
|
Gnu GCC Temporary Files Symlink Arbitrary File Overwrite
|
|
10646
Description:
GNU gettext contains a flaw that may allow a malicious local user to overwrite arbitrary files. The issue is due to temporary files being created insecurely. It is possible that the flaw may allow a malicious user to overwrite arbitrary files resulting in a loss of integrity.
|
2004-10-11
|
GNU gettext Multiple Script Temporary File Symlink Arbitrary File Overwrite
|
|
4676
Description:
When the -dSAFER option is in use, Ghostscript should not open piped commands (i.e. %pipe%cmd). This is not the case due to improper handling of the %pipe% I/O device. An attacker could trick a user into opening a specially crafted Postscript file to exploit this vulnerability; resulting in arbitrary code execution with the users privileges, on the local system.
|
2003-05-17
|
GNU Ghostscript -dSAFER %pipe% Flaw Arbitrary Command Execution
|
|
12650
Description:
(Description Provided by CVE) : ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
|
2001-09-18
|
GNU ghostscript Arbitrary File Read
|
|
69533
Description:
GNU Gnash contains a flaw related to the configure script functionality. The issue is triggered when a local attacker uses symlink attacks to overwrite arbitrary files with privileges of the user running the script.
|
2010-11-29
|
GNU Gnash Configure Script Temporary File Symlink Arbitrary File Overwrite
|
|
77243
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
|
2011-11-20
|
GNU Gnash Local Cookie Disclosure
|
|
37273
Description:
(Description Provided by CVE) : server/parser/sprite_definition.cpp in GNU Gnash (aka GNU Flash Player) 0.7.2 allows remote attackers to execute arbitrary code via a large number of SHOWFRAME elements within a DEFINESPRITE element, which triggers memory corruption and enables the attacker to call free with an arbitrary address, probably resultant from a buffer overflow.
|
2007-05-02
|
GNU Gnash sprite_definition.cpp DEFINESPRITE Element Arbitrary Code Execution
|
|
4607
Description:
GNU GNATS contains a flaw that may allow a local attacker to gain root privileges. The issue is due to a flaw in the misc.c file in which the configure() function is not properly checked for input. If a local attacker provides a specially crafted request, they may be able to overflow the buffer and execute arbitrary code with root privileges.
|
2003-06-21
|
GNU GNATS misc.c configure() Overflow
|