VendorsRed Hatredhat_package_manager4.0.2-72
Vulnerabilities

Red Hat RPM 4.0.2-72

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2002-2204
The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
Published 2005-11-16 · Modified
7.5EPSS 0.015
CVE-2001-0923
RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.
Published 2002-02-02 · Modified
7.2EPSS 0.006