TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution
cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pat
Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Tex
fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitr
The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which t
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileg
REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows loca
Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by t
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local us
The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cac
OmniSecure HTTProtect 1.1.1 allows a superuser without omnish privileges to modify a protected file by creating a symbol
tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, whic
Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding t
Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the
lsfs in AIX 4.x allows a local user to gain additional privileges by creating Trojan horse programs named (1) grep or (2
kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overf
Buffer overflow in the kcsSUNWIOsolf.so library in Solaris 7 and 8 allows local attackers to execute arbitrary commands
kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm ca
sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop pr
Identix BioLogon 2.03 and earlier does not lock secondary displays on a multi-monitor system running Windows 98 or ME, w
SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary
Buffer overflow in the Xview library as used by mailtool in Solaris 8 and earlier allows a local attacker to gain privil
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain t
Buffer overflow in mailx in Solaris 8 and earlier allows a local attacker to gain additional privileges via a long '-F'
Digital Creations Zope 2.3.2 and earlier allows a local attacker to gain additional privileges via the changing of ZClas
Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker
Buffer overflow in Vixie cron 3.0.1-56 and earlier could allow a local attacker to gain additional privileges via a long
Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long fi
lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a b
Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a lo
Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbitrary files via a '..' (dot dot) a
TrendMicro ScanMail for Exchange 3.5 Evaluation allows a local attacker to recover the administrative credentials for Sc
sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain ad
asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain add
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with suff
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read th
Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can rea
Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into
NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the stud
EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.
Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes
Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group ma
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
A buffer overflow in reggo.dll file used by Trend Micro InterScan VirusWall prior to 3.51 build 1349 for Windows NT 3.5
Buffer overflow in mail included with SunOS 5.8 for x86 allows a local user to gain privileges via a long HOME environme
Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to exec
Alexis 2.0 and 2.1 in COM2001 InternetPBX stores voicemail passwords in plain text in the com2001.ini file, which could
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started