Latest CVE Feed
-
2.1
LOWCVE-2004-1032
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0996
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1439
NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.... Read more
Affected Products : mac_os_x- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0977
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0656
eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.... Read more
Affected Products : eroaster- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1587
/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.... Read more
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0923
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0482
Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a "date -s" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.... Read more
Affected Products : linux_kernel- Published: Jan. 31, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0040
APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.... Read more
Affected Products : apcupsd- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2725
The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.... Read more
Affected Products : rtos- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4176
AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.... Read more
Affected Products : award_bios_modular- Published: Dec. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2554
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.... Read more
Affected Products : epolicy_orchestrator_agent- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-1420
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and... Read more
- Published: Mar. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-0432
Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly pro... Read more
Affected Products : weblogic_server- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0380
A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel memory.... Read more
Affected Products : freebsd- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2533
OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.... Read more
Affected Products : openvpn- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0620
iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file, which ha... Read more
Affected Products : calendar_server- Published: Aug. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1705
Oracle Database 9.2.0.0 to 10.2.0.3 allows local users with "SELECT" privileges for a base table to insert, update, or delete data by creating a crafted view then performing the operations on that view.... Read more
- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0110
Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the passwords from the file.... Read more
Affected Products : miramail- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3486
Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) via u... Read more
- Published: Jul. 10, 2006
- Modified: Apr. 03, 2025