Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly exec
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local use
The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprot
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to
The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to
aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating
The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitiv
The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary file
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair gener
NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in t
ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which al
Buffer overflow in xlockmore xlock program version 4.16 and earlier allows local users to read sensitive data from memor
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denia
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in pla
Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package P
eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords
Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent to the Central Alert Se
SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configur
A Windows NT administrator account has the default name of Administrator.
Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key
The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifie
Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.
LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages
Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain she
The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink atta
DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symli
FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF im
Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.
Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malfo
The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a
Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network inte
LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world e
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is s
shred 1.0 file wiping utility does not properly open a file for overwriting or flush its buffers, which prevents shred f
WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.
Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, w
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.
The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary file
A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before th
Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to
nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial o
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a
Scan for 2000 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started