IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" r
Denial of service in Linux 2.2.0 running the ldd command on a core file.
Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.
IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags"
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users t
Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry key
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious prog
SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service
ftp on HP-UX 11.00 allows local users to gain privileges.
Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.
Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.
Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the
In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the "noexec" fla
XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories
Local users can gain privileges using the debug utility in the MPE/iX operating system.
Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE)
Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name
The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache c
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of servic
Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to by
screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty
useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argum
The KDE klock program allows local users to unlock a session using malformed input.
Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow lo
Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.
MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.
FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variab
Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local
E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the
Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal
gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in
Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2)
Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable an
mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.
ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local
Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.
Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local user
Scan for 1999 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started