Sentex Jhead vulnerabilities
4 known vulnerabilities affecting sentex/jhead.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2008-4641CRITICALCVSS 10.0≤ 2.82v1.2+18 more2008-10-21
CVE-2008-4641 [CRITICAL] CWE-20 CVE-2008-4641: The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to exec
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.
nvd
CVE-2008-4639MEDIUMCVSS 4.6≤ 2.84v1.2+19 more2008-10-21
CVE-2008-4639 [MEDIUM] CWE-59 CVE-2008-4639: jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files vi
jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
nvd
CVE-2008-4640LOWCVSS 3.6≤ 2.82v1.2+18 more2008-10-21
CVE-2008-4640 [LOW] CWE-20 CVE-2008-4640: The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to de
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.
nvd
CVE-2008-4575MEDIUMCVSS 5.0≤ 2.82v1.2+18 more2008-10-15
CVE-2008-4575 [MEDIUM] CWE-119 CVE-2008-4575: Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attacke
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."
nvd