Vulnerabilities > Unix

DATE CVE VULNERABILITY TITLE RISK
2010-01-13 CVE-2009-3958 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat and Acrobat Reader
Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.
network
low complexity
adobe apple microsoft unix CWE-119
critical
10.0
2010-01-13 CVE-2009-3957 Denial of Service vulnerability in Adobe Reader and Acrobat Null Pointer Dereference
Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors.
network
low complexity
adobe apple microsoft unix
5.0
2010-01-13 CVE-2009-3956 Configuration vulnerability in Adobe Acrobat and Acrobat Reader
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.
network
low complexity
adobe apple microsoft unix CWE-16
critical
10.0
2010-01-13 CVE-2009-3954 Code Injection vulnerability in Adobe Acrobat and Acrobat Reader
The 3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to execute arbitrary code via unspecified vectors, related to a "DLL-loading vulnerability." Per: http://www.adobe.com/support/security/bulletins/apsb10-02.html Affected software versions Adobe Reader 9.2 and earlier versions for Windows, Macintosh, and UNIX Adobe Acrobat 9.2 and earlier versions for Windows and Macintosh Per: http://www.adobe.com/support/security/bulletins/apsb10-02.html a DLL-loading vulnerability in 3D that could allow arbitrary code execution (CVE-2009-3954).
network
low complexity
adobe apple microsoft unix CWE-94
critical
10.0
2009-06-22 CVE-2009-2166 Path Traversal vulnerability in Ocsinventory-Ng OCS Inventory NG 1.0/1.01/1.02
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
network
low complexity
ocsinventory-ng unix CWE-22
5.0
2009-04-14 CVE-2009-1292 Information Exposure vulnerability in IBM Rational Clearcase
UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.
local
low complexity
ibm unix CWE-200
2.1
2009-04-09 CVE-2009-1251 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.
network
low complexity
unix openafs CWE-119
critical
10.0
2008-11-05 CVE-2008-4815 Permissions, Privileges, and Access Controls vulnerability in Adobe Acrobat and Acrobat Reader
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.
network
low complexity
unix adobe CWE-264
7.5
2008-01-31 CVE-2008-0525 Link Following vulnerability in multiple products
PatchLink Update client for Unix, as used by Novell ZENworks Patch Management Update Agent for Linux/Unix/Mac (LUM) 6.2094 through 6.4102 and other products, allows local users to (1) truncate arbitrary files via a symlink attack on the /tmp/patchlink.tmp file used by the logtrimmer script, and (2) execute arbitrary code via a symlink attack on the /tmp/plshutdown file used by the rebootTask script.
local
low complexity
unix lumension-security novell CWE-59
4.6
2007-12-10 CVE-2007-6305 Buffer Errors vulnerability in IBM Hardware Management Console 7.3.2.0
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 7 R3.2.0 allow attackers to gain privileges via "some HMC commands."
local
low complexity
linux unix ibm CWE-119
4.6