OVAL Definitions - Family: unix

Title Definition Id Class Family
The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits... oval:org.mitre.oval:def:9586 Vulnerability unix
The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arb... oval:org.mitre.oval:def:11054 Vulnerability unix
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 befor... oval:org.mitre.oval:def:9804 Vulnerability unix
The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, an... oval:org.mitre.oval:def:9570 Vulnerability unix
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 befor... oval:org.mitre.oval:def:11569 Vulnerability unix
The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers t... oval:org.mitre.oval:def:10393 Vulnerability unix
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows rem... oval:org.mitre.oval:def:10537 Vulnerability unix
The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) ... oval:org.mitre.oval:def:9871 Vulnerability unix
The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.1... oval:org.mitre.oval:def:9552 Vulnerability unix
The RPL dissector in Wireshark (formerly Ethereal) 0.9.8 to 0.99.6 allows remote attackers to cause a denial of service ... oval:org.mitre.oval:def:11442 Vulnerability unix
The rsh package should not be installed oval:gov.irs.rhel5:def:136 Compliance unix
The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop... oval:org.mitre.oval:def:10732 Vulnerability unix
The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perf... oval:org.mitre.oval:def:11556 Vulnerability unix
The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval... oval:org.mitre.oval:def:9807 Vulnerability unix
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0... oval:org.mitre.oval:def:11530 Vulnerability unix
The Samba smbd service should be enabled or disabled as approriate oval:gov.irs.sol10:def:21 Compliance unix
The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow us... oval:org.mitre.oval:def:9876 Vulnerability unix
The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel does not check for t... oval:org.mitre.oval:def:9364 Vulnerability unix
The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to... oval:org.mitre.oval:def:11816 Vulnerability unix
The SCTP dissector in Wireshark (formerly Ethereal) 0.99.5 through 0.99.7 allows remote attackers to cause a denial of s... oval:org.mitre.oval:def:11378 Vulnerability unix
The SCTP-netfilter code in Linux kernel before allows remote attackers to trigger a denial of service (infinit... oval:org.mitre.oval:def:10373 Vulnerability unix
The sctp_new function in (1) ip_conntrack_proto_sctp.c and (2) nf_conntrack_proto_sctp.c in Netfilter in Linux kernel 2.... oval:org.mitre.oval:def:10116 Vulnerability unix
The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel and earlier, when SCTP is e... oval:org.mitre.oval:def:11416 Vulnerability unix
The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause... oval:org.mitre.oval:def:11160 Vulnerability unix
The search_binary_handler function in exec.c in Linux 2.4 kernel on 64-bit x86 architectures does not check a return cod... oval:org.mitre.oval:def:10649 Vulnerability unix
The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an en... oval:org.mitre.oval:def:10580 Vulnerability unix
The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_c... oval:org.mitre.oval:def:10193 Vulnerability unix
The selinux_ptrace logic in hooks.c in SELinux for Linux 2.6.6 allows local users with ptrace permissions to change the ... oval:org.mitre.oval:def:10102 Vulnerability unix
The sendmail services should be enabled or disabled as appropriate. oval:gov.irs.sol10:def:5 Compliance unix
The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local user... oval:org.mitre.oval:def:9311 Vulnerability unix

