Latest CVE Feed
-
3.6
LOWCVE-2001-1409
dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.... Read more
- Published: Jul. 24, 2003
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2012-4417
GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.... Read more
Affected Products : glusterfs- Published: Nov. 18, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2014-6543
Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to ITEM (Item & BOM).... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2014-9683
Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileg... Read more
- Published: Mar. 03, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2014-8527
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information and affect integrity via vectors related to a "plain text password."... Read more
Affected Products : network_data_loss_prevention- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2014-5459
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache func... Read more
- Published: Sep. 27, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2010-1626
MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.... Read more
- Published: May. 21, 2010
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2008-0819
Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.... Read more
Affected Products : plutostatus_locator- Published: Feb. 19, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2008-0822
Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a .. (dot dot) in the page parameter.... Read more
Affected Products : scribe- Published: Feb. 19, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2008-0806
wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file.... Read more
Affected Products : wyrd- Published: Feb. 19, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2008-2148
The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary fil... Read more
Affected Products : linux_kernel- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2006-0353
unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed informatio... Read more
Affected Products : lsh- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2015-3164
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.... Read more
- Published: Jul. 01, 2015
- Modified: Aug. 29, 2025
-
3.6
LOWCVE-2008-4228
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows physically proximate attackers to leverage the emergency-call ability of locked devices to make a phone call to an arbitrary number.... Read more
- Published: Nov. 25, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2005-0576
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.... Read more
Affected Products : solaris- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-3707
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 and 9.0.3.1 has unknown impact and attack vectors, aka Oracle Vuln# AS02.... Read more
Affected Products : application_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-2995
bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in.... Read more
Affected Products : bacula- Published: Sep. 20, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-3589
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the S... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-2582
Kaspersky Anti-Virus for Unix/Linux File Servers 5.0-5 uses world-writable permissions for the (1) log and (2) license directory, which allows local users to delete log files, append to arbitrary files via a symlink attack on kavmonitor.log, or delete lic... Read more
Affected Products : kaspersky_anti-virus- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-2617
The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application w... Read more
Affected Products : linux_kernel- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025