Search CVE reports


Toggle filters

11 – 20 of 29 results


CVE-2008-1291

Low priority
Ignored

ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.

2 affected packages

viewcvs, viewvc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
viewcvs
viewvc
Show less packages

CVE-2008-1290

Low priority
Ignored

ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.

2 affected packages

viewcvs, viewvc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
viewcvs
viewvc
Show less packages

CVE-2007-0246

Unknown priority
Ignored

plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.

1 affected package

gforge-plugin-scmcvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
gforge-plugin-scmcvs
Show less packages

CVE-2007-0347

Unknown priority
Ignored

The is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service...

1 affected package

cvstrac

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cvstrac
Show less packages

CVE-2005-4830

Unknown priority

Some fixes available 5 of 8

CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter.

2 affected packages

viewcvs, viewvc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
viewcvs
viewvc
Show less packages

CVE-2005-2693

Unknown priority
Fixed

cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.

2 affected packages

cvs, gcvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cvs
gcvs
Show less packages

CVE-2004-1342

Unknown priority
Fixed

CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.

1 affected package

cvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cvs
Show less packages

CVE-2005-0753

Unknown priority
Fixed

Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.

1 affected package

cvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cvs
Show less packages

CVE-2004-0915

Unknown priority
Fixed

Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote attackers to gain sensitive information.

2 affected packages

viewcvs, viewvc

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
viewcvs
viewvc
Show less packages

CVE-2004-1343

Unknown priority
Fixed

CVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).

1 affected package

cvs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cvs
Show less packages