Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencode
Multiple race conditions in the handling of O_DIRECT in Linux kernel prior to version 2.4.22 could cause stale data to b
Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service
Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attacker
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send req
Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive informati
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to
faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to m
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obta
The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-
The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause
The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a de
Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of serv
NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the
Symbolic link vulnerability in xbreaky before 0.5.5 allows local users to overwrite arbitrary files via a symlink from t
Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges.
ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an inco
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port
Memory leak in lofiadm in Solaris 8 allows local users to cause a denial of service (kernel memory consumption).
psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/bef
ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary f
BitchX IRC client 1.0c20cvs and earlier allows attackers to cause a denial of service (core dump) via certain channel mo
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Solaris 8 may allow loc
Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwr
Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows
The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the cal
The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/sel
/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow lo
GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a sy
Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary file
WatchGuard ServerLock for Windows 2000 before SL 2.0.4 allows local users to access kernel memory via a symlink attack o
eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is u
Sustworks IPNetSentryX and IPNetMonitorX allow local users to sniff network packets via the setuid helper applications (
Unknown vulnerability in the libcpr library for the Checkpoint/Restart (cpr) system on SGI IRIX 6.5.21f and earlier allo
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
Finder in Mac OS X 10.2.8 and earlier sets global read/write/execute permissions on directories when they are dragged (c
slpd daemon in Mac OS X before 10.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying pa
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to c
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blo
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, w
Certain scripts in OpenServer before 5.0.6 allow local users to overwrite files and conduct other unauthorized activitie
Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite a
Zebra 0.93b and earlier, and quagga before 0.95, allows local users to cause a denial of service by sending spoofed mess
ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorize
shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local u
ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows u
Rit Research Labs The Bat! 1.0.11 through 2.0 creates new accounts with insecure ACLs, which allows local users to read
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the Cl
Scan for 2003 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started