Gentoo
201 known vulnerabilities
Top Products
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-cont
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a defaul
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's mach
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to m
pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on file
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downlo
Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and
Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injection, leadin
USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because
Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directo
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might a
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which migh
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabb
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and de
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls fo
The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local u
flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-
Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows lo
Frequently Asked Questions
How many CVEs affect Gentoo?
Gentoo has 201 CVE records in our database, including 4 critical and 86 high severity vulnerabilities.
What are the most severe Gentoo vulnerabilities?
Gentoo has 4 critical severity (CVSS 9.0+) and 86 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Gentoo vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gentoo products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Gentoo Vulnerabilities
CyberStrike scans your infrastructure for Gentoo vulnerabilities and provides real-time remediation guidance.
Get Started