Latest CVE Feed
-
1.2
LOWCVE-2001-1276
ispell before 3.1.20 allows local users to overwrite files of other users via a symlink attack on a temporary file.... Read more
Affected Products : ispell- Published: Jun. 21, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-1073
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the fil... Read more
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2002-1674
procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to.... Read more
Affected Products : freebsd- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2003-1061
Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.... Read more
- Published: Oct. 14, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0095
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.... Read more
Affected Products : sunos- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1331
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.... Read more
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0887
xSANE 0.81 and earlier allows local users to modify files of other xSANE users via a symlink attack on temporary files.... Read more
- Published: Jan. 15, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0118
rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-3440
The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirmation.... Read more
- Published: Nov. 11, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2006-0591
The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen... Read more
Affected Products : crypt_blowfish- Published: Feb. 08, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-4761
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D ... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-0448
Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.... Read more
Affected Products : perl- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1286
Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the full pathname when executing a process.... Read more
Affected Products : bitdefender_antivirus- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1824
Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.... Read more
Affected Products : phpguestbook- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1167
SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local users to obtain sensitive information.... Read more
Affected Products : propack- Published: Feb. 06, 2007
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2006-1059
The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.... Read more
Affected Products : samba- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2008-3259
OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX... Read more
Affected Products : openssh- Published: Jul. 22, 2008
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2006-4232
Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.... Read more
Affected Products : globus_toolkit- Published: Aug. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-3118
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary f... Read more
Affected Products : spread- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-3011
The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : texinfo- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025