Search CVE reports
11 – 20 of 29 results
CVE-2008-1291
Low priorityViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.
2 affected packages
viewcvs, viewvc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
viewcvs | — | — | — | — | — |
viewvc | — | — | — | — | — |
CVE-2008-1290
Low priorityViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.
2 affected packages
viewcvs, viewvc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
viewcvs | — | — | — | — | — |
viewvc | — | — | — | — | — |
CVE-2007-0246
Unknown priorityplugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.
1 affected package
gforge-plugin-scmcvs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
gforge-plugin-scmcvs | — | — | — | — | — |
CVE-2007-0347
Unknown priorityThe is_eow function in format.c in CVSTrac before 2.0.1 does not properly check for the "'" (quote) character, which allows remote authenticated users to execute limited SQL injection attacks and cause a denial of service...
1 affected package
cvstrac
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cvstrac | — | — | — | — | — |
CVE-2005-4830
Unknown prioritySome fixes available 5 of 8
CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter.
2 affected packages
viewcvs, viewvc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
viewcvs | — | — | — | — | — |
viewvc | — | — | — | — | — |
CVE-2005-2693
Unknown prioritycvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
2 affected packages
cvs, gcvs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cvs | — | — | — | — | — |
gcvs | — | — | — | — | — |
CVE-2004-1342
Unknown priorityCVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.
1 affected package
cvs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cvs | — | — | — | — | — |
CVE-2005-0753
Unknown priorityBuffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.
1 affected package
cvs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cvs | — | — | — | — | — |
CVE-2004-0915
Unknown priorityMultiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which could allow remote attackers to gain sensitive information.
2 affected packages
viewcvs, viewvc
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
viewcvs | — | — | — | — | — |
viewvc | — | — | — | — | — |
CVE-2004-1343
Unknown priorityCVS 1.12 and earlier on Debian GNU/Linux does not properly handle when a mapping for the current repository does not exist in the cvs-repouids file, which allows remote attackers to cause a denial of service (server crash).
1 affected package
cvs
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
cvs | — | — | — | — | — |