Cdrtools
4 CVEs tracked since 2003. Since May 2003, none of them reached CISA KEV.
Cdrtools CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2003-05 | 1 | 0 |
| 2003-06 | null or fewer | |
| 2003-07 | null or fewer | |
| 2003-08 | 1 | 0 |
| 2003-09 | null or fewer | |
| 2003-10 | null or fewer | |
| 2003-11 | null or fewer | |
| 2003-12 | null or fewer | |
| 2004-01 | null or fewer | |
| 2004-02 | null or fewer | |
| 2004-03 | null or fewer | |
| 2004-04 | null or fewer | |
| 2004-05 | null or fewer | |
| 2004-06 | null or fewer | |
| 2004-07 | null or fewer | |
| 2004-08 | null or fewer | |
| 2004-09 | 1 | 0 |
| 2004-10 | null or fewer | |
| 2004-11 | null or fewer | |
| 2004-12 | null or fewer | |
| 2005-01 | null or fewer | |
| 2005-02 | null or fewer | |
| 2005-03 | 1 | 0 |
Products
The products that kept showing up in Cdrtools's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Cdrtools.
- CVE-2005-0866cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.2.1
- CVE-2004-0806cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local ...7.2
- CVE-2003-0655rscsi in cdrtools 2.01 and earlier allows local users to overwrite arbitrary files and gain root privileges by specifying the target file as a command line argument, which is modified while rscsi i...7.2
- CVE-2003-0289Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.7.2
The record
- Peak rank
- #22 in Aug 2003
- Busiest month shown
- May 2003, 1 CVEs
- Months with a KEV entry
- 0 since May 2003
- Monthly snapshots
- 4 since 2003