Latest CVE Feed
-
2.1
LOWCVE-2005-0346
SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process.... Read more
Affected Products : softremote_vpn_client- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0161
Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.... Read more
Affected Products : unace- Published: Feb. 22, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-2623
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.3 allows local users to affect confidentiality via unknown vectors.... Read more
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-0798
Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service.... Read more
Affected Products : hp-ux- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1538
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's pas... Read more
Affected Products : internet_information_server- Published: Jan. 14, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1109
securetar, as used in AMaViS shell script 0.2.1 and earlier, allows users to cause a denial of service (CPU consumption) via a malformed TAR file, possibly via an incorrect file size parameter.... Read more
Affected Products : virus_scanner- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1586
Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.... Read more
- Published: Dec. 03, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1470
SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file.... Read more
Affected Products : shoutcast_server- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-4011
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : bea_product_suite- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-0002
The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existen... Read more
Affected Products : bash- Published: Jan. 14, 2010
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-1740
Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter).... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1125
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory.... Read more
Affected Products : freebsd- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0429
BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions.... Read more
Affected Products : weblogic_server- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1348
Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.... Read more
Affected Products : linux- Published: Jun. 30, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2136
dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.... Read more
Affected Products : linux_kernel- Published: Feb. 19, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0662
scrollkeeper-get-cl in ScrollKeeper 0.3 to 0.3.11 allows local users to create and overwrite files via a symlink attack on the scrollkeeper-tempfile.x temporary files.... Read more
- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-0009
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.... Read more
Affected Products : linux_kernel- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-1430
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as... Read more
Affected Products : davinci- Published: Jan. 01, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1229
Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.... Read more
Affected Products : quake_2_server- Published: Feb. 25, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1764
acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : acrobat_reader- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025