Latest CVE Feed
-
3.6
LOWCVE-2008-0822
Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a .. (dot dot) in the page parameter.... Read more
Affected Products : scribe- Published: Feb. 19, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2015-6927
vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containe... Read more
Affected Products : vzctl- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2002-1509
A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users in the same group to read or modify the new user's incoming email.... Read more
Affected Products : linux- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2014-2477
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect integrity and availability via unknown vectors related to Core, a different ... Read more
Affected Products : vm_virtualbox- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2002-0044
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.... Read more
- Published: Jan. 31, 2002
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2012-1620
slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.... Read more
Affected Products : slock- Published: Jul. 12, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-3225
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality and integrity, related to BASE.... Read more
Affected Products : financial_services_software- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-0808
as31 2.3.1-4 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack.... Read more
Affected Products : as31- Published: Mar. 19, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-3750
The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.... Read more
Affected Products : iphone_os- Published: Nov. 03, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2014-1875
The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : capture-tiny- Published: Oct. 06, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2012-0109
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows local users to affect confidentiality and availability, related to TCP/IP.... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-1699
The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service... Read more
- Published: Dec. 21, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2020-1807
HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.188(C00E74R3P8) have an improper authorization vulnerability. The software does not properly restrict certain user's modification of certain configuration file, successful exploit could allow th... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
3.6
LOWCVE-2006-5406
Passgo Defender 5.2 creates the application directory with insecure permissions (Everyone/Full Control), which allows local users to read and modify sensitive files. NOTE: the provenance of this information is unknown; the details are obtained from third... Read more
Affected Products : defender- Published: Oct. 19, 2006
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2015-0794
modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.... Read more
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2020-4008
The installer of the macOS Sensor for VMware Carbon Black Cloud (prior to 3.5.1) handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which a macOS sensor is going to be installed, may overwrite a limited num... Read more
- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024
-
3.6
LOWCVE-2019-0178
Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.... Read more
- Published: Jun. 13, 2019
- Modified: Nov. 21, 2024
-
3.6
LOWCVE-2023-39342
Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzone CLI (`dangerzone-cli` command) logs output from the container where the file sanitization takes place, to the user's terminal. Prior... Read more
Affected Products : dangerzone- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
3.6
LOWCVE-2000-0802
The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.... Read more
Affected Products : personal_privacy- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2007-1150
Unrestricted file upload vulnerability in LoveCMS 1.4 allows remote authenticated administrators to upload arbitrary files to /modules/content/pictures/tmp/.... Read more
Affected Products : lovecms- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025