CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 2.1 | dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files. |
| 1mo ago | 2.1 | Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file. |
| 1mo ago | 3.6 | The default permissions for Endymion MailMan allow local users to read email or modify files. |
| 1mo ago | 3.6 | UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission. |
| 1mo ago | 2.1 | Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack. |
| 1mo ago | 2.1 | Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly. |
| 1mo ago | 2.1 | FreeBSD gdc program allows local users to modify files via a symlink attack. |
| 1mo ago | 2.1 | Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets. |
| 1mo ago | 2.6 | Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. |
| 1mo ago | 2.1 | Denial of service in BIND named via naptr. |
| 1mo ago | 3.6 | cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system. |
| 1mo ago | 3.6 | Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL. |
| 1mo ago | 2.6 | By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. |
| 1mo ago | 2.6 | Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key. |
| 1mo ago | 2.1 | userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack. |
| 1mo ago | 2.1 | shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code. |
| 1mo ago | 2.1 | FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files. |
| 1mo ago | 2.1 | The SSH authentication agent follows symlinks via a UNIX domain socket. |
| 1mo ago | 2.1 | sccw allows local users to read arbitrary files. |
| 1mo ago | 2.1 | FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers. |
| 1mo ago | 2.1 | FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes. |
| 1mo ago | 2.1 | Trn allows local users to overwrite other users' files via symlinks. |
| 1mo ago | 2.1 | The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links. |
| 1mo ago | 2.1 | Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load. |
| 1mo ago | 2.6 | Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. |
| 1mo ago | 2.6 | Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. |
| 1mo ago | 2.1 | Denial of service in AIX ptrace system call allows local users to crash the system. |
| 1mo ago | 3.6 | OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices. |
| 1mo ago | 2.1 | Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems. |
| 1mo ago | 2.1 | Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users. |