CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 0 | A DNS server allows zone transfers. |
| 1mo ago | 2.1 | ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i. |
| 1mo ago | 2.1 | MajorCool mj_key_cache program allows local users to modify files via a symlink attack. |
| 1mo ago | 2.1 | Denial of service in Qmail by specifying a large number of recipients with the RCPT command. |
| 1mo ago | 2.1 | SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device. |
| 1mo ago | 2.1 | The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket. |
| 1mo ago | 2.1 | Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost. |
| 1mo ago | 0 | A version of finger is running that exposes valid user information to any entity on the network. |
| 1mo ago | 2.1 | Finger redirection allows finger bombs. |
| 1mo ago | 2.1 | finger allows recursive searches by using a long string of @ symbols. |
| 1mo ago | 0 | A version of rusers is running that exposes valid user information to any entity on the network. |
| 1mo ago | 0 | IP traceroute is allowed from arbitrary hosts. |
| 1mo ago | 2.1 | Denial of service in syslog by sending it a large number of superfluous messages. |
| Exploit 1mo ago | 2.1 | Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service. |
| 1mo ago | 2.1 | dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file. |
| 1mo ago | 2.1 | Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access. |
| 1mo ago | 2.1 | fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access. |
| 1mo ago | 2.1 | cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files. |
| Exploit 1mo ago | 2.1 | nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information. |
| 1mo ago | 2.1 | Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands. |
| 1mo ago | 1.9 | pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. |
| 1mo ago | 3.7 | Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet. |
| 1mo ago | 3.7 | Race condition in Linux mailx command allows local users to read user files. |
| 1mo ago | 2.1 | colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument. |
| 1mo ago | 2.1 | The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone. |
| 1mo ago | 2.1 | Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files. |
| 1mo ago | 0 | The rexd service is running, which uses weak authentication that can allow an attacker to execute commands. |
| 1mo ago | 2.1 | /usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users. |
| 1mo ago | 3.1 | Insufficient policy enforcement in AI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a crafted HTML page. (Chromium security severity: Medium) |