openpkg CVE Vulnerabilities & CVE List (27)

Products (CPE): — CVEs: 27

openpkg vulnerability overview

Aggregates CVE and security vulnerability intelligence across all openpkg-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk buffer overflow, vendor risk memory corruption, and vendor risk input validation; exposure may include vendor impact memory corruption in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 2127 of 27 CVEs
«« First « Prev Page 2 / 2 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2004-0594 The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization of key data structures is complete. [email protected] 5.1 54.86% 2004-07-27 2026-04-16
CVE-2004-1997 Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges. [email protected] 4.6 0.45% 2004-05-05 2026-04-16
CVE-2003-0615 Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter. [email protected] 4.3 4.44% 2003-08-27 2026-06-16
CVE-2003-0190 OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack. [email protected] 5.0 76.75% 2003-05-12 2026-06-16
CVE-2003-0147 OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal). [email protected] 5.0 6.39% 2003-03-31 2026-06-16
CVE-2002-0985 Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and possibly executing commands. [email protected] 7.5 2.95% 2002-09-24 2026-06-16
CVE-2002-0083 Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. [email protected] 9.8 14.80% 2002-03-15 2026-06-16
«« First « Prev Page 2 / 2 Next »
cvelogic Threat Intelligence