Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption
Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Window
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, a
The binfmt functionality in the Linux kernel, when "memory overcommit" is enabled, allows local users to cause a denial
dispatch-conf in Portage 2.0.51-r2 and earlier allows local users to overwrite arbitrary files via a symlink attack on t
qpkg in Gentoolkit 0.2.0_pre10 and earlier allows local users to overwrite arbitrary files via a symlink attack on a tem
The mtink status monitor before 1.0.5 for Epson printers allows local users to overwrite arbitrary files via a symlink a
KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by t
SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that h
FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman
lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt th
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lpp
IglooFTP 0.6.1, when recursively uploading a directory, allows local users to overwrite the files that are being uploade
The slip_down function in slip.c for the uml_net program in uml-utilities 20030903, when uml_net is installed setuid roo
zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arb
Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, whi
getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitr
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local us
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access
useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allow
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local use
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secu
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and po
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows
The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other oper
The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating sys
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users t
The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows lo
Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local us
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attac
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which a
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Clie
Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem
Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archi
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local use
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows loc
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows l
reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local us
reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser a
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by cal
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create
Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypas
sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig para
delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" pa
Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local user
Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLI
Scan for 2005 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started