Latest CVE Feed
-
2.1
LOWCVE-2005-0580
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.... Read more
Affected Products : cmd5checkpw- Published: Feb. 25, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0406
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.... Read more
Affected Products : samba- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0568
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory... Read more
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-5790
The Globe7 soft phone client 7.3 uses weak cryptography (reversed sequence of binary values) for the password, which might allow local users to obtain sensitive information.... Read more
Affected Products : globe7- Published: Nov. 01, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-3789
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.... Read more
Affected Products : samba- Published: Aug. 27, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2001-0568
Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.... Read more
Affected Products : zope- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0461
/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.... Read more
Affected Products : linux- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6340
Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain cleartext passwords.... Read more
- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-6418
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.... Read more
Affected Products : debian_linux- Published: Dec. 18, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-0518
VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password.... Read more
- Published: Apr. 06, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-0456
The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.... Read more
- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1400
Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock).... Read more
- Published: Apr. 17, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2016-0605
Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-0119
Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."... Read more
- Published: Feb. 25, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-0582
Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2, when storing forwarded credentials, allows attackers to overwrite arbitrary files and change file ownership via unknown vectors.... Read more
Affected Products : heimdal- Published: Feb. 08, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0079
The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.... Read more
Affected Products : hanterm-xf- Published: Mar. 03, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1608
The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.... Read more
Affected Products : php- Published: Apr. 10, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4605
The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1860
lease_init in fs/locks.c in Linux kernel before 2.6.16.16 allows attackers to cause a denial of service (fcntl_setlease lockup) via actions that cause lease_init to free a lock that might not have been allocated on the stack.... Read more
Affected Products : linux_kernel- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-5701
Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "ca un... Read more
Affected Products : lotus_domino- Published: Oct. 29, 2007
- Modified: Apr. 09, 2025