Rpath is a modestly represented vendor whose vulnerability disclosures center on its Linux distribution and appliance platform products, positioning it as a niche participant in the embedded and specialized-system space. The recurring weakness classes—information exposure, link-following conditions, and memory-boundary issues—reflect the low-level system and filesystem mechanics inherent to Linux kernel and initialization infrastructure, and public exploit code has an elevated tendency to emerge for these disclosures. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rpath over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5962HIGH Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows rem | May 22, 2008 | 7.1 | 34 | NO | YES |
CVE-2008-0411MEDIUM Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file con | Feb 28, 2008 | 6.8 | 33 | NO | YES |
CVE-2006-6235HIGH A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets | Dec 7, 2006 | 10.0 | 26 | NO | NO |
CVE-2007-5116HIGH Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching | Nov 7, 2007 | 7.5 | 23 | NO | NO |
CVE-2007-1351HIGH Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execut | Apr 6, 2007 | 8.5 | 23 | NO | NO |
CVE-2008-5516HIGH The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_search. | Jan 20, 2009 | 7.5 | 22 | NO | NO |
CVE-2008-3138MEDIUM The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vect | Jul 10, 2008 | 5.0 | 19 | NO | NO |
CVE-2007-5194MEDIUM The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as /dev/port, which might allow lo | Oct 4, 2007 | 6.9 | 19 | NO | NO |
CVE-2007-4131MEDIUM Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (sl | Aug 25, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-3106MEDIUM lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via inv | Jul 26, 2007 | 6.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rpath.
Media articles that mention a CVE ID that affects a product developed by Rpath — matched by CVE ID, not by vendor name.