CVE Tracker
159,027 total CVEsLive vulnerability feed from the National Vulnerability Database
MajorCool mj_key_cache program allows local users to modify files via a symlink attack.
rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.
Command execution in Sun systems via buffer overflow in the at program.
getcwd() file descriptor leak in FTP.
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.
Denial of service in IIS using long URLs.
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.
Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.
Buffer overflow in AIX lquerylv program gives root access to local users.
IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.
cfingerd lists all users on a system via search.**@target.
Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.
SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.
Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.
Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.
Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.
Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.
Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.
Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.
Showing 158726-158750 of 159,027 CVEs