Latest CVE Feed
-
1.2
LOWCVE-2005-1368
The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.... Read more
Affected Products : linux_kernel- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1396
Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.... Read more
Affected Products : ce_ceterm- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-2678
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#pas... Read more
- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2001-0119
getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1066
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-1781
SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs s... Read more
Affected Products : systemtap- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2011-4415
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a d... Read more
Affected Products : http_server- Published: Nov. 08, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2016-0431
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0419.... Read more
Affected Products : solaris- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2007-3108
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.... Read more
Affected Products : openssl- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2012-6095
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.... Read more
Affected Products : proftpd- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-5214
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2015-4822
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2015-4831.... Read more
Affected Products : solaris- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2006-1066
Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack du... Read more
Affected Products : linux_kernel- Published: Mar. 27, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-3011
The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : texinfo- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-2666
SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a lis... Read more
Affected Products : openssh- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-3440
The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirmation.... Read more
- Published: Nov. 11, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2002-0435
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it ... Read more
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0959
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.... Read more
Affected Products : glibc- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-1999-1486
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : aix- Published: Feb. 25, 1998
- Modified: Apr. 03, 2025