CVE Tools

Rpath

9 CVEs tracked since 2007. Since Apr 2007, none of them reached CISA KEV.

Rpath CVEs per month

Apr 2007 to Jul 2008. Point at a month, or focus the strip and use the arrow keys.
Rpath CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2007-0420
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-1020
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-0530
2008-06null or fewer
2008-0720

Products

The products that kept showing up in Rpath's monthly top three, with their CVEs summed over those months.

  1. Rpath Linux43 months
  2. Appliance Platform Agent31 month
  3. Linux11 month
  4. Rmake11 month

Latest CVEs

The 13 most recently published vulnerabilities affecting Rpath.

  1. CVE-2008-4832rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. NOTE: this issue ...6.9
  2. CVE-2008-3139The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: this might be due to a use-after-f...5.0
  3. CVE-2008-3138The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vectors.5.0
  4. CVE-2007-5962Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to ...7.1
  5. CVE-2008-2140Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted ...2.6
  6. CVE-2008-2139The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes i...6.5
  7. CVE-2008-1078expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOT...7.2
  8. CVE-2007-5686initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd de...4.9
  9. CVE-2007-5194The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as /dev/port, which might allow local users to gain...6.9
  10. CVE-2007-1352Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which r...3.8
  11. CVE-2007-1351Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code ...8.5
  12. CVE-2007-0536The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain privileges.7.2
  13. CVE-2006-6235A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG...10.0

The record

Peak rank
#32 in May 2008
Busiest month shown
May 2008, 3 CVEs
Months with a KEV entry
0 since Apr 2007
Monthly snapshots
4 since 2007
Rpath's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store