Where
AND
-Infinity
0
Severity
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N

rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N

BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N

/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N

Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

X fontserver xfs allows local users to cause a denial of service via malformed input to the server.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N

Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N

Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

dumpreg in Red Hat Linux 5.1 opens /dev/mem with ORDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N

gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N

Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.

First published (updated )
Severity
3.6
AV:L/AC:L/Au:N/C:N/I:P/A:P

apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOWPOWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N

glibc 2.1.9x and earlier does not properly clear the RESOLVHOSTCONF, HOSTALIASES, or RESOPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

gettyps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.

First published (updated )
Severity
2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N

When using the LDPRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.

First published (updated )
Severity
1.2
AV:L/AC:H/Au:N/C:N/I:P/A:N

inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203