Page 5 of 50 results (0.003 seconds)

CVSS: 9.6EPSS: 5%CPEs: 62EXPL: 1

14 Sep 2004 — Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain. • http://bugzilla.mozilla.org/show_bug.cgi?id=250862 •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

31 Dec 2002 — Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors. • http://www.securityfocus.com/bid/6329 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 10.0EPSS: 0%CPEs: 74EXPL: 13

14 Nov 2000 — Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. • https://www.exploit-db.com/exploits/249 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.8EPSS: 0%CPEs: 24EXPL: 3

22 May 2000 — Buffer overflow in fdmount on Linux systems allows local users in the "floppy" group to execute arbitrary commands via a long mountpoint parameter. • https://www.exploit-db.com/exploits/19952 •

CVSS: 7.8EPSS: 0%CPEs: 14EXPL: 1

22 Mar 2000 — gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root. • https://www.exploit-db.com/exploits/19816 •

CVSS: 7.5EPSS: 4%CPEs: 11EXPL: 1

16 Aug 1999 — A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service. • https://www.exploit-db.com/exploits/19463 •

CVSS: 7.8EPSS: 0%CPEs: 7EXPL: 0

30 Mar 1999 — XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. • http://www.securityfocus.com/bid/359 •

CVSS: 7.8EPSS: 0%CPEs: 14EXPL: 1

21 Mar 1999 — XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. • https://www.exploit-db.com/exploits/19257 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

17 Mar 1999 — suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk. • http://www.securityfocus.com/bid/339 •

CVSS: 7.8EPSS: 0%CPEs: 28EXPL: 2

18 Feb 1999 — A buffer overflow in lsof allows local users to obtain root privilege. • https://www.exploit-db.com/exploits/19373 •