Latest CVE Feed
-
1.2
LOWCVE-2008-3259
OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX... Read more
Affected Products : openssh- EPSS Score: %0.03
- Published: Jul. 22, 2008
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2011-1769
SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script tha... Read more
Affected Products : systemtap- EPSS Score: %0.07
- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2001-0142
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.... Read more
- EPSS Score: %0.08
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0141
mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.... Read more
Affected Products : mgetty- EPSS Score: %0.08
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2013-4476
Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the... Read more
Affected Products : samba- EPSS Score: %0.23
- Published: Nov. 13, 2013
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2001-1331
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.... Read more
- EPSS Score: %0.07
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2016-0431
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0419.... Read more
Affected Products : solaris- EPSS Score: %0.12
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2006-0741
Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service ("endless recursive fault") via unknown attack vectors related to a "bad elf entry address."... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2014-3537
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.... Read more
- EPSS Score: %0.05
- Published: Jul. 23, 2014
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2011-2722
The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.... Read more
Affected Products : linux_imaging_and_printing_project- EPSS Score: %0.03
- Published: May. 25, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2002-1563
stunnel 4.0.3 and earlier allows attackers to cause a denial of service (crash) via SIGCHLD signal handler race conditions that cause an inconsistency in the child counter.... Read more
Affected Products : stunnel- EPSS Score: %0.08
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2002-2001
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.15
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2015-0489
Unspecified vulnerability in the Application Management Pack for Oracle E-Business Suite component in Oracle E-Business Suite AMP 121030 and 121020 allows local users to affect confidentiality via vectors related to EBS Plugin.... Read more
Affected Products : e-business_suite_application_management_pack- EPSS Score: %0.15
- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2008-5450
Unspecified vulnerability in the Oracle Applications Platform Engineering component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows local users to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %0.20
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2012-4676
The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary files by constructing a (1) symlink or (2) hard link, a different vulnerability than CVE-2012-3485.... Read more
Affected Products : tunnelblick- EPSS Score: %0.04
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2006-1167
SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local users to obtain sensitive information.... Read more
Affected Products : propack- EPSS Score: %0.07
- Published: Feb. 06, 2007
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2001-0095
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.... Read more
Affected Products : sunos- EPSS Score: %0.14
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2014-6134
IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sens... Read more
- EPSS Score: %0.12
- Published: Mar. 25, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2000-0154
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.... Read more
Affected Products : unixware- EPSS Score: %0.29
- Published: Feb. 16, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-4761
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D ... Read more
Affected Products : weblogic_server- EPSS Score: %0.11
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025