Latest CVE Feed
-
2.1
LOWCVE-2005-2076
HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.... Read more
Affected Products : version_control_repository_manager- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1977
Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.... Read more
Affected Products : pgp- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0507
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous u... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0712
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.... Read more
Affected Products : entrust_authority_security_manager- Published: Feb. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0499
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.... Read more
Affected Products : linux_kernel- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0595
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.... Read more
- Published: Jan. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0559
eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.... Read more
Affected Products : etrust_intrusion_detection- Published: Jun. 07, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-3067
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.... Read more
- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2000-0167
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.... Read more
Affected Products : internet_information_server- Published: Feb. 15, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0754
Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.... Read more
Affected Products : openview_network_node_manager- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-2367
Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by reading these files.... Read more
Affected Products : certificate_system- Published: Jan. 20, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2000-0462
ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.... Read more
Affected Products : netbsd- Published: May. 28, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1827
Sendmail 8.9.0 through 8.12.3 allows local users to cause a denial of service by obtaining an exclusive lock on the (1) alias, (2) map, (3) statistics, and (4) pid files.... Read more
Affected Products : sendmail- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0633
Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.... Read more
- Published: Jul. 18, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0322
The open() function in FreeBSD allows local attackers to write to arbitrary files.... Read more
Affected Products : freebsd- Published: Oct. 29, 1997
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0890
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.... Read more
- Published: Dec. 11, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1782
The default configuration of University of Washington IMAP daemon (wu-imapd), when running on a system that does not allow shell access, allows a local user with a valid IMAP account to read arbitrary files as that user.... Read more
Affected Products : uw-imap- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1976
ifconfig, when used on the Linux kernel 2.2 and later, does not report when the network interface is in promiscuous mode if it was put in promiscuous mode using PACKET_MR_PROMISC, which could allow attackers to sniff the network without detection, as demo... Read more
Affected Products : linux_kernel- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0577
Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.... Read more
Affected Products : hp-ux- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0445
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.... Read more
Affected Products : pgp- Published: May. 24, 2000
- Modified: Apr. 03, 2025