Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrativ
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local user
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of
SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWAT
Antivir / Linux 2.0.9-9, and possibly earlier versions, allows local users to overwrite arbitrary files via a symlink at
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlin
dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV com
Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite
The System Configuration subsystem in Mac OS 10.2.8 and 10.3.2 allows local users to modify network settings, a differen
The System Configuration subsystem in Mac OS 10.2.8 allows local users to modify network settings, a different vulnerabi
The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard dis
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to re
Citadel/UX 5.00 through 6.14 installs the database directory and files with world-read permissions, which could allow lo
kmod in the Linux kernel does not set its uid, suid, gid, or sgid to 0, which allows local users to cause a denial of se
xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the
Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (
Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (syste
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomi
Multiple vulnerabilities in suidperl 5.6.1 and earlier allow a local user to obtain sensitive information about files fo
The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IP
mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport tem
cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV c
The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the
The OSS code for the Sound Blaster (sb16) driver in Linux 2.4.x before 2.4.26, when operating in 16 bit mode, does not p
The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the
The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.
The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a m
flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emac
The log_event function in ssmtp 2.50.6 and earlier allows local users to overwrite arbitrary files via a symlink attack
The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count coun
BEA WebLogic Server and WebLogic Express 7.0 through SP5 and 8.1 through SP2 does not enforce site restrictions for star
Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password i
Datakey Rainbow iKey2032 USB token, when using the CIP client package, does not encrypt communications between the token
The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system cra
Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system pan
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows l
Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an inf
Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service
The Equalizer Load-balancer for serial network interfaces (eql.c) in Linux kernel 2.6.x up to 2.6.7 allows local users t
Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module
Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the
Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of
msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack
Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary fi
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwr
A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to t
The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary fi
Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows lo
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started