Vulnerabilities > Selinux

DATE CVE VULNERABILITY TITLE RISK
2008-05-23 CVE-2007-5496 Cross-Site Scripting vulnerability in Selinux Setroubleshoot 2.0.5
Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.
1.9
2008-05-23 CVE-2007-5495 Link Following vulnerability in Selinux Setroubleshoot 2.0.5
sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file.
4.4