WebTrends software stores account names and passwords in a file which does not have restricted access permissions.
Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which cou
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append
Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local u
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to
Denial of service in AIX ptrace system call allows local users to crash the system.
Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load
The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic link
Trn allows local users to overwrite other users' files via symlinks.
FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number acc
FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs u
sccw allows local users to read arbitrary files.
The SSH authentication agent follows symlinks via a UNIX domain socket.
FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.
shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decryp
userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.
Denial of service in BIND named via naptr.
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets
FreeBSD gdc program allows local users to modify files via a symlink attack.
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse prope
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a pla
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of ar
Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.
Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.
Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of serv
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which a
FTPPro allows local users to read sensitive information, which is stored in plain text.
nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite
lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line par
Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to o
Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectiv
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such a
netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is s
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a sy
Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was
Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32
Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functio
GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has l
A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-bas
/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environmen
Lynx allows a local user to overwrite sensitive files through /tmp symlinks.
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.
A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitiv
Anonymous FTP is enabled.
ICMP echo (ping) is allowed from arbitrary hosts.
Scan for 1999 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started