Latest CVE Feed
-
2.1
LOWCVE-2005-3341
DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh.... Read more
Affected Products : dns_package- Published: Dec. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2851
smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.... Read more
Affected Products : smb4k- Published: Sep. 08, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-4145
nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to ... Read more
Affected Products : networkmanager- Published: Dec. 23, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-0223
Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext d... Read more
- Published: Jan. 07, 2010
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-0124
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : employee_timeclock_software- Published: Mar. 15, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2946
fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning ... Read more
- Published: Sep. 29, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2913
The Citibank Citi Mobile app before 2.0.3 for iOS stores account data in a file, which allows local users to obtain sensitive information via vectors involving (1) the mobile device or (2) a synchronized computer.... Read more
- Published: Jul. 30, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0995
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.... Read more
- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-0675
The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the dr... Read more
Affected Products : linux_kernel- Published: Feb. 22, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2011-0797
Unspecified vulnerability in the Applications Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2603
RIM BlackBerry Desktop Software 4.7 through 6.0 for PC, and 1.0 for Mac, uses a weak password to encrypt a database backup file, which makes it easier for local users to decrypt the file via a brute force attack.... Read more
- Published: Dec. 17, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2574
Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.... Read more
Affected Products : mantisbt- Published: Aug. 10, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-1162
The tpm_read function in the Linux kernel 2.6 does not properly clear memory, which might allow local users to read the results of the previous TPM command.... Read more
Affected Products : linux_kernel- Published: Jan. 27, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-0441
IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive informati... Read more
Affected Products : tivoli_business_service_manager- Published: Jan. 25, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-2797
xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.... Read more
- Published: Aug. 27, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-6418
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.... Read more
Affected Products : debian_linux- Published: Dec. 18, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2011-3212
CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate attackers to obtain sensitive information by reading directly from the disk d... Read more
- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-2784
Google Chrome before 13.0.782.107 allows remote attackers to obtain sensitive information via a request for the GL program log, which reveals a local path in an unspecified log entry.... Read more
Affected Products : chrome- Published: Aug. 03, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-1022
Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from with... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2011-2493
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel before 2.6.39 does not properly initialize a certain error-report data structure, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesy... Read more
Affected Products : linux_kernel- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025