Latest CVE Feed
-
1.2
LOWCVE-2004-0814
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attack... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-4415
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a d... Read more
Affected Products : http_server- Published: Nov. 08, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2004-0404
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.... Read more
Affected Products : logcheck- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-0050
snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.... Read more
Affected Products : debian_linux- Published: Mar. 23, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0119
getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-3163
HP MFP Digital Sending Software 4.9x through 4.91.21 allows local users to obtain sensitive workflow-metadata information via unspecified vectors.... Read more
Affected Products : multifunction_peripheral_digital_sending_software- Published: Oct. 23, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2012-2313
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.... Read more
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2000-0210
The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.... Read more
Affected Products : workshop- Published: Feb. 21, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1066
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1396
Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.... Read more
Affected Products : ce_ceterm- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0154
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.... Read more
Affected Products : unixware- Published: Feb. 16, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1176
Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.... Read more
Affected Products : aix- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1231
CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.... Read more
Affected Products : capi4hylafax- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0117
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.... Read more
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-3118
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary f... Read more
Affected Products : spread- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2007-0832
VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct ce... Read more
Affected Products : workstation- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2006-5298
The mutt_adv_mktemp function in the Mutt mail client 1.5.12 and earlier does not properly verify that temporary files have been created with restricted permissions, which might allow local users to create files with weak permissions via a race condition b... Read more
Affected Products : mutt- Published: Oct. 16, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2007-0833
VMware Workstation 5.5.3 34685, when the "Enable copy and paste to and from this virtual machine" option is enabled, preserves clipboard data on the guest operating system after it was deleted on the host operating system, which might allow local users to... Read more
Affected Products : workstation- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2010-3014
The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which trigger... Read more
- Published: Aug. 20, 2010
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2005-4761
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D ... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025