Latest CVE Feed
-
1.2
LOWCVE-2004-0880
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.... Read more
- EPSS Score: %0.10
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-2724
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of ... Read more
Affected Products : samba- EPSS Score: %0.93
- Published: Sep. 06, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2006-5757
Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data s... Read more
Affected Products : linux_kernel- EPSS Score: %0.60
- Published: Nov. 06, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2001-0143
vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.07
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- EPSS Score: %0.18
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1066
Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack du... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 27, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-2678
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#pas... Read more
- EPSS Score: %0.24
- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2005-3011
The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : texinfo- EPSS Score: %0.04
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0120
useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.07
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-4232
Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.... Read more
Affected Products : globus_toolkit- EPSS Score: %0.07
- Published: Aug. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0119
getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.07
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2004-0814
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attack... Read more
- EPSS Score: %0.24
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2010-3718
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demo... Read more
Affected Products : tomcat- EPSS Score: %0.25
- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2013-2217
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.... Read more
- EPSS Score: %0.07
- Published: Sep. 23, 2013
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2004-1058
Race condition in Linux kernel 2.6 allows local users to read the environment variables of another process that is still spawning via /proc/.../cmdline.... Read more
- EPSS Score: %0.06
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-6306
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.... Read more
Affected Products : client- EPSS Score: %0.08
- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2005-4761
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D ... Read more
Affected Products : weblogic_server- EPSS Score: %0.11
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-1061
Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.... Read more
- EPSS Score: %0.06
- Published: Oct. 14, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1301
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.... Read more
- EPSS Score: %0.19
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-4676
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file.... Read more
Affected Products : rendezvous- EPSS Score: %0.44
- Published: Sep. 11, 2006
- Modified: Apr. 03, 2025