Latest CVE Feed
-
3.6
LOWCVE-2011-4406
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.... Read more
- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2015-4231
The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.... Read more
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2013-0254
The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or... Read more
- Published: Feb. 06, 2013
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2014-8737
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or fu... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2014-6543
Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to ITEM (Item & BOM).... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2008-2288
Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 has insufficient access control for deletion and modification of registry keys, which allows local users to cause a denial of service or obtain sensitive information.... Read more
Affected Products : altiris_deployment_solution- Published: May. 18, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2012-1620
slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.... Read more
Affected Products : slock- Published: Jul. 12, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-5638
The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.... Read more
Affected Products : sanlock- Published: Dec. 20, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2010-2391
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5 and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.... Read more
Affected Products : database_server- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2014-1875
The Capture::Tiny module before 0.24 for Perl allows local users to write to arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : capture-tiny- Published: Oct. 06, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2012-1699
The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service... Read more
- Published: Dec. 21, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-6150
The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access... Read more
- Published: Dec. 03, 2013
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2020-1807
HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.188(C00E74R3P8) have an improper authorization vulnerability. The software does not properly restrict certain user's modification of certain configuration file, successful exploit could allow th... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
3.6
LOWCVE-2015-2660
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to Oracle Agile PLM Framework.... Read more
Affected Products : supply_chain_products_suite- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2015-2633
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.0.1 and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Ops Center.... Read more
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2012-1122
bug_actiongroup.php in MantisBT before 1.2.9 does not properly check the report_bug_threshold permission of the receiving project when moving a bug report, which allows remote authenticated users with the report_bug_threshold and move_bug_threshold privil... Read more
Affected Products : mantisbt- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2013-4956
Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if those permissions were used when the modules were originally... Read more
- Published: Aug. 20, 2013
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2006-4759
PunBB 1.2.12 does not properly handle an avatar directory pathname ending in %00, which allows remote authenticated administrative users to upload arbitrary files and execute code, as demonstrated by a query to admin_options.php with an avatars_dir parame... Read more
Affected Products : punbb- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2013-4426
pyxtrlock before 0.1 uses an incorrect variable name, which allows physically proximate attackers to bypass the lock screen via multiple failed authentication attempts, which trigger a crash.... Read more
Affected Products : pyxtrlock- Published: May. 19, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2013-1500
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unkn... Read more
- Published: Jun. 18, 2013
- Modified: Apr. 11, 2025