Latest CVE Feed
-
3.6
LOWCVE-2007-5936
dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place.... Read more
- Published: Nov. 13, 2007
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2025-27574
Cross-site scripting vulnerability exists in the USB storage file-sharing function of HGW-BL1500HM Ver 002.002.003 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the configu... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Cross-Site Scripting
-
3.6
LOWCVE-2015-3164
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.... Read more
- Published: Jul. 01, 2015
- Modified: Aug. 29, 2025
-
3.6
LOWCVE-2008-2148
The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary fil... Read more
Affected Products : linux_kernel- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2024-38531
Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible... Read more
- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
3.6
LOWCVE-2010-1439
yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network pro... Read more
- Published: Jun. 07, 2010
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2010-3586
Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integrity via unknown vectors related to XScreenSaver.... Read more
- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2006-4246
Usermin before 1.220 (20060629) allows remote attackers to read arbitrary files, possibly related to chfn/save.cgi not properly handling an empty shell parameter, which results in changing root's shell instead of the shell of a specified user.... Read more
Affected Products : usermin- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2010-3028
The Aardvertiser component before 2.2.1 for Joomla! uses insecure permissions (777) in unspecified folders, which allows local users to modify, create, or delete certain files.... Read more
- Published: Aug. 16, 2010
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2006-2147
resmgrd in resmgr for SUSE Linux and other distributions does not properly handle when access to a USB device is granted by using "usb:<bus>,<dev>" notation, which grants access to all USB devices and allows local users to bypass intended restrictions. N... Read more
Affected Products : resmgrd- Published: May. 02, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2009-1189
The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an inc... Read more
Affected Products : dbus- Published: Apr. 27, 2009
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2010-1172
DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Po... Read more
Affected Products : dbus-glib- Published: Aug. 20, 2010
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2006-2045
The (1) shadow password file in na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has world readable permissions, which allows local users to view encrypted passwords; and the (2) NetAccess database file has world readable and writable permissions, wh... Read more
Affected Products : ip3_netaccess_75- Published: Apr. 26, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2009-0834
The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass cert... Read more
- Published: Mar. 06, 2009
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2012-1120
The SOAP API in MantisBT before 1.2.9 does not properly enforce the bugnote_allow_user_edit_delete and delete_bug_threshold permissions, which allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bu... Read more
Affected Products : mantisbt- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-2451
The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it ... Read more
Affected Products : config-inifiles- Published: Jun. 27, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2005-2995
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.... Read more
Affected Products : bacula- Published: Sep. 20, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-3070
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.... Read more
Affected Products : hylafax- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-0180
Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the... Read more
Affected Products : linux_kernel- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2014-4372
syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.... Read more
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025