strace allows local users to read arbitrary files via memory mapped file names.
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.
Cisco Cache Engine allows a remote attacker to gain access via a null username and password.
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.
The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.
Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.
Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.
The default permissions for Endymion MailMan allow local users to read email or modify files.
dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.
UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.
Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
FreeBSD gdc program allows local users to modify files via a symlink attack.
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
Denial of service in BIND named via naptr.