Gentoo is a distribution and package-management ecosystem where vulnerabilities are largely inherited from upstream open-source projects rather than originating in Gentoo's own codebases, reflecting its role as a source-based Linux distribution that compiles components at the user's site. The vendor's disclosed vulnerabilities span a diverse set of widely used tools and libraries—including the Linux kernel, the Portage package manager, log-rotation utilities, web-administration frameworks, and cluster-management software—each carrying the weakness patterns endemic to their respective domains. Weakness classes recur around permission and resource-access issues, information exposure, and input-validation gaps, reflecting both the heterogeneous nature of aggregated upstream flaws and the inherent complexity of privilege boundaries in Unix-like systems and administrative tools. While the severity profile remains moderate, a notable tendency emerges toward public exploit availability, which is consistent with Gentoo's broad footprint across system administration and server environments where disclosures are rapidly weaponized. Defenders should treat Gentoo advisories as pointers to upstream vulnerability remediation rather than as Gentoo-specific flaws; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gentoo over time
Signals from CVEs in this vendor scope (198 CVEs).
198 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2004-0608HIGH The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, | Dec 6, 2004 | 10.0 | 81 | NO | YES |
CVE-2002-1337HIGH Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a | Mar 7, 2003 | 10.0 | 80 | NO | YES |
CVE-2004-1037HIGH The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string. | Mar 1, 2005 | 10.0 | 76 | NO | YES |
CVE-2024-12084CRITICAL A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIG | Jan 15, 2025 | 9.8 | 75 | NO | NO |
CVE-2012-2982MEDIUM file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) char | Sep 11, 2012 | 6.5 | 74 | NO | YES |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-2004-0493MEDIUM The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error lead | Aug 6, 2004 | 6.4 | 72 | NO | YES |
CVE-2004-0932HIGH McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via | Jan 27, 2005 | 7.5 | 71 | NO | YES |
CVE-2004-0990HIGH Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code | Mar 1, 2005 | 10.0 | 50 | NO | YES |
Signals from CVEs in this vendor scope (198 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gentoo.
Media articles that mention a CVE ID that affects a product developed by Gentoo — matched by CVE ID, not by vendor name.