SEPTEMBER 22, 2026
Live Feed
Vulnerability Register

CVE Database

Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update

16,139 records on file
Page 532 of 538
CVE ID Score Description
1mo ago
2.6

Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.

1mo ago
2.1

The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.

1mo ago
2.6

ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.

1mo ago
2.1

The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.

1mo ago
2.1

aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.

1mo ago
2.1

The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.

1mo ago
2.1

The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.

1mo ago
2.1

Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.

1mo ago
2.1

The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.

1mo ago
3.6

The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.

1mo ago
2.1

Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.

1mo ago
2.6

Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.

1mo ago
2.1

Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.

1mo ago
2.1

X fontserver xfs allows local users to cause a denial of service via malformed input to the server.

1mo ago
2.1

The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.

1mo ago
2.1

BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.

1mo ago
2.1

CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.

1mo ago
2.1

The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.

1mo ago
2.6

Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.

1mo ago
2.6

A remote attacker can read information from a Netscape user's cache via JavaScript.

1mo ago
2.1

Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.

1mo ago
2.1

Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.

1mo ago
2.1

The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.

1mo ago
2.1

Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.

1mo ago
1.2

The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.

1mo ago
1.2

The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.

1mo ago
1.2

ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.

1mo ago
2.1

IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.

1mo ago
2.1

snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host's configuration.

1mo ago
3.6

Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.