Searching set parms software vulnerabilities


An unrestricted remote trust relationship for U


An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.


Solaris 2.4 before kernel jumbo patch -35 allow


Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.


Cayman 3220-H DSL Router 1.0 ship without a pas


Cayman 3220-H DSL Router 1.0 ship without a password set, which allows remote attackers to gain unauthorized access.


The Install Wizard for nCipher MSCAPI CSP 5.50


The Install Wizard for nCipher MSCAPI CSP 5.50 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).


domesticinstall.exe for nCipher MSCAPI CSP 5.50


domesticinstall.exe for nCipher MSCAPI CSP 5.50 and 5.54 does not use Operator Card Set protected keys when the user requests them but does not generate the Operator Card Set, which results in a lower protection level than specified by the user (module protection only).


index.php in dotProject 0.2.1.5 allows remote a


index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.


"Memory bugs" in OpenSSH 3.7.1 and earlier, wit


"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.


Internet Explorer 6 on Double Byte Character Se


Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."


Race condition in Squid 2.5.STABLE7 to 2.5.STAB


Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.


SQL injection vulnerability in the SYS.DBMS_CDC


SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.


set_lang.php in phpMyVisites 1.3 allows remote


set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.


Certain system calls in Apple Mac OS X 10.4.1 d


Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.


The (1) Kate and (2) Kwrite applications in KDE


The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.


eRoom does not set an expiration for Cookies, w


eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks.


phpldapadmin before 0.9.6c allows remote attack


phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set.


MiniGal 2 (MG2) 0.5.1 allows remote attackers t


MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.


NetBSD 1.6 up to 3.0, when a user has "set reco


NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.


Multiple unspecified format string vulnerabilit


Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.


IBM Informix Dynamic Server (IDS) allows remote


IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands.


The perfstat kernel extension in bos.perf.perfs


The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.


Software vulnerabilities results 1 to 20 of 406     
Page: 12345...21