CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 2.1 | BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device. |
| 1mo ago | 2.1 | Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service. |
| 1mo ago | 2.1 | WebTrends software stores account names and passwords in a file which does not have restricted access permissions. |
| 1mo ago | 2.1 | Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist. |
| 1mo ago | 2.1 | The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked. |
| 1mo ago | 2.1 | The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack. |
| 1mo ago | 2.6 | When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information. |
| 1mo ago | 3.6 | Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail. |
| 1mo ago | 2.6 | A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. |
| 1mo ago | 2.6 | The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. |
| 1mo ago | 2.1 | A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable. |
| 1mo ago | 2.1 | Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS. |
| 1mo ago | 2.1 | The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred. |
| 1mo ago | 1.2 | A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail. |
| 1mo ago | 2.1 | Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. |
| 1mo ago | 2.1 | talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes. |
| 1mo ago | 2.1 | 64 bit Solaris 7 procfs allows local users to perform a denial of service. |
| 1mo ago | 2.1 | IMail POP3 daemon uses weak encryption, which allows local users to read files. |
| 1mo ago | 1.2 | The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack. |
| 1mo ago | 2.1 | Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry. |
| 1mo ago | 2.1 | OpenBSD crash using nlink value in FFS and EXT2FS filesystems. |
| 1mo ago | 2.1 | Buffer overflow in OpenBSD ping. |
| 1mo ago | 2.6 | Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD. |
| 1mo ago | 2.1 | Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service. |
| 1mo ago | 2.1 | xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file. |
| 1mo ago | 2.6 | A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service. |
| 1mo ago | 2.1 | Debian GNU/Linux cfengine package is susceptible to a symlink attack. |
| 1mo ago | 2.1 | Vulnerability in Compaq Tru64 UNIX edauth command. |
| 1mo ago | 2.1 | The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. |
| 1mo ago | 1.2 | Lynx allows a local user to overwrite sensitive files through /tmp symlinks. |