Latest CVE Feed
-
3.6
LOWCVE-2014-1351
Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.... Read more
Affected Products : iphone_os- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2014-1257
CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.... Read more
- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2011-4434
Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by ... Read more
- Published: Nov. 11, 2011
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2007-6208
sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.... Read more
Affected Products : claws_mail_tools- Published: Dec. 04, 2007
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2007-5851
iChat in Apple Mac OS X 10.4.11 allows network-adjacent remote attackers to automatically initiate a video connection to another user via unknown vectors.... Read more
Affected Products : mac_os_x- Published: Dec. 19, 2007
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-1999-0850
The default permissions for Endymion MailMan allow local users to read email or modify files.... Read more
Affected Products : mailman_webmail- Published: Dec. 02, 1999
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-0946
apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologi... Read more
Affected Products : linux- Published: Dec. 04, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-1753
A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : debian_linux- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-1524
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this de... Read more
Affected Products : linux_kernel- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2001-1079
create_keyfiles in PSSP 3.2 with DCE 3.1 authentication on AIX creates keyfile directories with world-writable permissions, which could allow a local user to delete key files and cause a denial of service.... Read more
Affected Products : aix- Published: Feb. 13, 2002
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2007-1537
\Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the N... Read more
- Published: Mar. 20, 2007
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2006-2045
The (1) shadow password file in na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has world readable permissions, which allows local users to view encrypted passwords; and the (2) NetAccess database file has world readable and writable permissions, wh... Read more
Affected Products : ip3_netaccess_75- Published: Apr. 26, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2015-0794
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.... Read more
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2006-4625
PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.... Read more
Affected Products : php- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2012-1120
The SOAP API in MantisBT before 1.2.9 does not properly enforce the bugnote_allow_user_edit_delete and delete_bug_threshold permissions, which allows remote authenticated users with read and write SOAP API privileges to delete arbitrary bug reports and bu... Read more
Affected Products : mantisbt- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2000-0270
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.... Read more
Affected Products : emacs- Published: Apr. 18, 2000
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2000-0667
Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.... Read more
Affected Products : linux- Published: Jul. 27, 2000
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2002-2334
Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.... Read more
Affected Products : joe- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2003-1234
Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_coun... Read more
Affected Products : freebsd- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-0202
Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writ... Read more
Affected Products : php_toolkit- Published: Jan. 13, 2006
- Modified: Apr. 03, 2025