| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| cfingerd lists all users on a system via search.**@target. |
| Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access. |
| A malicious Palace server can force a client to execute arbitrary programs. |
| MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. |
| The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail. |
| Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files. |
| Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits. |
| Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command. |
| Denial of service through Solaris 2.5.1 telnet by sending ^D characters. |
| ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption. |
| mSQL v2.0.1 and below allows remote execution through a buffer overflow. |
| The WorkMan program can be used to overwrite any file to get root access. |
| Excite for Web Servers (EWS) allows remote command execution via shell metacharacters. |
| Unknown vulnerability in HP OpenVMS VAX 7.x and 6.x and OpenVMS Alpha 7.x or 6.x allows local users to access privileged files. |
| ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book. |
| The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory. |
| Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file. |
| SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise. |
| Unknown vulnerability in the SG_IO functionality in ide-cd allows local users to bypass read-only access and perform unauthorized write and erase operations. |
| Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbitrary code via a certain environment variable. |