Vulnerabilities > Netscape > Portable Runtime API > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-10-12 | CVE-2006-4842 | Improper Input Validation vulnerability in multiple products The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files. | 3.6 |