The (1) libsasl and (2) libsasl2 libraries in Cyrus-SASL 2.1.18 and earlier trust the SASL_PATH environment variable to
SUSE Linux Enterprise Server 9 on the S/390 platform does not properly handle a certain privileged instruction, which al
Multiple buffer overflows in the enable command for SCO OpenServer 5.0.6 and 5.0.7 allow local users to execute arbitrar
stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allow
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Se
Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and lo
A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sens
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create
Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under
Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions,
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5
The load_elf_library in the Linux kernel before 2.6.11.6 allows local users to cause a denial of service (kernel crash)
Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrar
Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary
Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.
McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain pri
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a
nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client funct
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with
Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage file
Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2
The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privile
Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before p
Multiple buffer overflows in the XView library 3.2 may allow local users to execute arbitrary code via setuid applicatio
Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allow
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete
ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via sh
Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string speci
Format string vulnerability in auditselect on IBM AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via
Buffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argume
Buffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.
MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encr
Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute ar
Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileg
ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADP
Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group poli
Buffer overflow in the IMAP daemon (IMAP4d32.exe) for Ipswitch Collaboration Suite (ICS) before 8.15 Hotfix 1 allows rem
Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.
Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local use
Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.
Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME
Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, relat
Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local us
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allow
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary
BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through th
Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleart
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format
Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XA
Scan for 2005 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started