Total vulnerabilities in the database
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
CVSS v2:
No CWE or OWASP classifications available.