The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify
The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeab
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libr
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variabl
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a pa
Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial o
Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is
The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS
Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).
Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denia
The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently
Certain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might all
Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a den
The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password
Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary comma
VERITAS Cluster Server (VCS) 1.3.0 on Solaris allows local users to cause a denial of service (system panic) via the -L
VShell SSH gateway 1.0.1 and earlier has a default port forwarding rule of 0.0.0.0/0.0.0.0, which could allow local user
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which m
sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does
makewhatis in the man package before 1.5i2 allows an attacker in group man to overwrite arbitrary files via a man page w
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malfor
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files w
vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swa
readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local
sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users t
Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.
Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attac
pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.
ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue qu
Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the Abou
Cisco CBOS 2.3.0.053 sends output of the "sh nat" (aka "show nat") command to the terminal of the next user who attempts
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during
Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files durin
Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in
Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrit
Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive e
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to atte
Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminat
sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the comma
iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP
QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsas
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kerne
Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilit
Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) Ob
IMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SEL
NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'de
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started