sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbit
gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are har
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a
OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow loc
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permiss
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98,
The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local us
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before execu
rfc1867.c in PHP before 5.0.2 allows local users to upload files to arbitrary locations via a PHP script with a certain
GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on l
The (1) inoregupdate, (2) uniftest, or (3) unimove scripts in eTrust InoculateIT for Linux 6.0 allow local users to over
Mailmgr 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/mailmgr.unsort, (2) /tmp/
Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via
Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a larg
Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secr
WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local us
SpiderSales shopping cart does not enforce a minimum length for the private key, which can make it easier for local user
Spider Sales shopping cart stores the private key in the same database and table as the public key, which allows local u
Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portio
The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure te
Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit
Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported fi
Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify t
The binary compatibility mode for FreeBSD 4.x and 5.x does not properly handle certain Linux system calls, which could a
FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call wi
Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a d
Integer overflow in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial o
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of ser
Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel c
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow
Multiple unknown vulnerabilities in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow
The tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on Debian Linux has world readable permissions,
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local user
The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwri
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arg
The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one proc
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote au
Unknown vulnerability in the SG_IO functionality in ide-cd allows local users to bypass read-only access and perform una
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDia
The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files
load_elf_binary in Linux before 2.4.26 allows local users to cause a denial of service (system crash) via an ELF binary
The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on t
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a
The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started