2 results (0.005 seconds)

CVSS: 2.1EPSS: 0%CPEs: 12EXPL: 0

silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file. • http://bugs.gentoo.org/show_bug.cgi?id=94587 http://secunia.com/advisories/16659 http://www.securityfocus.com/archive/1/409672 http://www.securityfocus.com/bid/14716 http://www.zataz.net/adviso/silc-server-toolkit-06152005.txt •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 1

Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information. • http://www.securityfocus.com/archive/1/309775 http://www.securityfocus.com/archive/1/309941/30/26090/threaded http://www.securityfocus.com/bid/6743 https://exchange.xforce.ibmcloud.com/vulnerabilities/11244 • CWE-255: Credentials Management Errors •