CVE Database

Search and browse vulnerability records from NVD

Showing 15 of 31215 CVEs

CVE ID Severity Description EPSS Published
5.5 MEDIUM

Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.

0.2% 2002-08-12
5.5 MEDIUM

script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command.

0.1% 2001-12-31
5.3 MEDIUM

Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE

26.9% 2001-12-31
5.5 MEDIUM

The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.

0.4% 2001-12-31
5.5 MEDIUM

qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.

0.3% 2001-08-31
5.5 MEDIUM

ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.

0.1% 2001-08-29
5.5 MEDIUM

Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.

0.1% 2001-04-17
5.5 MEDIUM

Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.

0.1% 2001-01-09
5.5 MEDIUM

HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.

1.7% 2000-12-19
5.5 MEDIUM

ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.

1.0% 2000-06-06
5.5 MEDIUM

Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.

1.3% 2000-04-23
5.5 MEDIUM

Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.

0.1% 1999-12-31
5.5 MEDIUM

FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.

0.2% 1998-06-16
5.4 MEDIUM

Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

11.0% 1998-04-08
5.4 MEDIUM

Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.

0.3% 1997-05-29