Search CVE reports


Toggle filters

11 – 20 of 30 results


CVE-2008-1292

Low priority
Ignored

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log...

2 affected packages

viewcvs, viewvc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
viewcvs
viewvc
Show less packages

CVE-2008-1291

Low priority
Ignored

ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.

2 affected packages

viewcvs, viewvc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
viewcvs
viewvc
Show less packages

CVE-2008-1290

Low priority
Ignored

ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.

2 affected packages

viewcvs, viewvc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
viewcvs
viewvc
Show less packages

CVE-2007-0347

Medium priority
Ignored

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service...

1 affected package

cvstrac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cvstrac
Show less packages

CVE-2007-0246

Medium priority
Ignored

plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.

1 affected package

gforge-plugin-scmcvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gforge-plugin-scmcvs
Show less packages

CVE-2005-4830

Medium priority

Some fixes available 5 of 8

CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter.

2 affected packages

viewcvs, viewvc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
viewcvs
viewvc
Show less packages

CVE-2005-2693

Medium priority
Fixed

cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.

2 affected packages

cvs, gcvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cvs
gcvs
Show less packages

CVE-2005-0753

Medium priority
Fixed

Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.

1 affected package

cvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cvs
Show less packages

CVE-2004-1343

Medium priority
Fixed

CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).

1 affected package

cvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cvs
Show less packages

CVE-2004-1342

Medium priority
Fixed

CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.

1 affected package

cvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cvs
Show less packages