VendorsGNUgnatsall versions
Vulnerabilities

GNU GNATS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2004-0623
Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.
Published 2004-06-30 · Modified
10.0EPSS 0.045
CVE-2007-2808
Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter.
Published 2007-05-22 · Modified
4.3EPSS 0.013
CVE-2005-2180
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.
Published 2005-07-10 · Modified
2.1EPSS 0.003