A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows l
OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.
Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.
cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allo
UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread pe
The default permissions for Endymion MailMan allow local users to read email or modify files.
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounti
Directory traversal vulnerability in Muhammad A. Muquit wwwcount (Count.cgi) 2.3 allows remote attackers to read arbitra
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the
A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial
Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.
The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" prot
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitra
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option,
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to
Cisco Cache Engine allows a remote attacker to gain access via a null username and password.
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the
strace allows local users to read arbitrary files via memory mapped file names.
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) f
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.
L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.
Solaris ff.core allows local users to modify files.
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access
Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
NetBSD netstat command allows local users to access kernel memory.
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not delet
Vulnerability in Compaq Tru64 UNIX edauth command.
Debian GNU/Linux cfengine package is susceptible to a symlink attack.
xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.
Buffer overflow in OpenBSD ping.
OpenBSD crash using nlink value in FFS and EXT2FS filesystems.
Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.
IMail POP3 daemon uses weak encryption, which allows local users to read files.
64 bit Solaris 7 procfs allows local users to perform a denial of service.
talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.
Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.
The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the p
Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link wi
A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-reada
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the ma
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempt
Scan for 1999 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started