Latest CVE Feed
-
1.2
LOWCVE-2010-3718
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demo... Read more
Affected Products : tomcat- EPSS Score: %0.25
- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2003-0462
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).... Read more
Affected Products : linux_kernel mandrake_linux mandrake_linux_corporate_server mandrake_multi_network_firewall- EPSS Score: %0.16
- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-0937
Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executin... Read more
- EPSS Score: %0.06
- Published: Feb. 22, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1059
The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.... Read more
Affected Products : samba- EPSS Score: %0.46
- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2004-1069
Race condition in SELinux 2.6.x through 2.6.9 allows local users to cause a denial of service (kernel crash) via SOCK_SEQPACKET unix domain sockets, which are not properly handled in the sock_dgram_sendmsg function.... Read more
- EPSS Score: %0.06
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2013-6891
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.... Read more
- EPSS Score: %0.05
- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2011-1769
SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script tha... Read more
Affected Products : systemtap- EPSS Score: %0.07
- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2011-2722
The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out temporary file.... Read more
Affected Products : linux_imaging_and_printing_project- EPSS Score: %0.03
- Published: May. 25, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2014-3537
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.... Read more
- EPSS Score: %0.05
- Published: Jul. 23, 2014
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2006-0741
Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service ("endless recursive fault") via unknown attack vectors related to a "bad elf entry address."... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-1781
SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs s... Read more
Affected Products : systemtap- EPSS Score: %0.06
- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2005-0448
Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.... Read more
Affected Products : perl- EPSS Score: %0.08
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- EPSS Score: %0.18
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0143
vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.07
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-6095
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.... Read more
Affected Products : proftpd- EPSS Score: %0.16
- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2005-2475
Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.... Read more
- EPSS Score: %0.08
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-5214
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed... Read more
- EPSS Score: %0.06
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2004-0404
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.... Read more
Affected Products : logcheck- EPSS Score: %0.07
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-3163
HP MFP Digital Sending Software 4.9x through 4.91.21 allows local users to obtain sensitive workflow-metadata information via unspecified vectors.... Read more
Affected Products : multifunction_peripheral_digital_sending_software- EPSS Score: %0.19
- Published: Oct. 23, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2012-2313
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.... Read more
- EPSS Score: %0.22
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025