299,877
Total vulnerabilities in the database
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.
| Software | From | Fixed in |
|---|---|---|
| jeremy_elson / tcpflow | 0.10 | 0.10.x |
| jeremy_elson / tcpflow | 0.20 | 0.20.x |
| jeremy_elson / tcpflow | 0.11 | 0.11.x |
| jeremy_elson / tcpflow | 0.12 | 0.12.x |