Aggregates CVE and security vulnerability intelligence across all gert_doering-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk path handling, vendor risk buffer overflow, and vendor risk denial of service, with potential vendor impact file overwrite across vendor surface software deployment use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2008-4936 | faxspool in mgetty 1.1.36 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/faxsp.##### temporary file. | [email protected] | 6.9 | 0.04% | 2008-11-05 | 2026-04-23 |
| CVE-2003-0516 | cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings. | [email protected] | 7.5 | 0.90% | 2003-08-18 | 2026-04-16 |
| CVE-2002-1392 | faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to modify fax transmission privileges. | [email protected] | 2.1 | 0.08% | 2003-01-17 | 2026-04-16 |
| CVE-2002-1391 | Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Caller ID string with a long CallerName argument. | [email protected] | 7.5 | 3.00% | 2003-01-17 | 2026-04-16 |
| CVE-2001-0141 | mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations. | [email protected] | 1.2 | 0.08% | 2001-03-12 | 2026-04-16 |
| CVE-2000-0691 | The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file. | [email protected] | 2.1 | 0.53% | 2000-10-20 | 2026-04-16 |