Latest CVE Feed
-
1.2
LOWCVE-2008-7256
mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict overcommit is enabled and CONFIG_SECURITY is disabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer derefer... Read more
Affected Products : linux_kernel- Published: Jun. 03, 2010
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2011-3163
HP MFP Digital Sending Software 4.9x through 4.91.21 allows local users to obtain sensitive workflow-metadata information via unspecified vectors.... Read more
Affected Products : multifunction_peripheral_digital_sending_software- Published: Oct. 23, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2012-2313
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.... Read more
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2004-0404
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.... Read more
Affected Products : logcheck- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2015-0489
Unspecified vulnerability in the Application Management Pack for Oracle E-Business Suite component in Oracle E-Business Suite AMP 121030 and 121020 allows local users to affect confidentiality via vectors related to EBS Plugin.... Read more
Affected Products : e-business_suite_application_management_pack- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2015-4823
Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1.2.3 allows local users to affect confidentiality via unknown vectors related to Essbase Rapid Deploy.... Read more
Affected Products : hyperion- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2004-0880
getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2024-49751
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Prior to commit 5d118a902872d7941f099ad1fb918e2421e79ccd, a user could inject HTML through SaaS signup inputs. The user... Read more
Affected Products :- Published: Oct. 23, 2024
- Modified: Oct. 25, 2024
-
1.2
LOWCVE-2006-6306
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.... Read more
Affected Products : client- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2012-6095
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.... Read more
Affected Products : proftpd- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2006-5214
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2006-5757
Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data s... Read more
Affected Products : linux_kernel- Published: Nov. 06, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2012-4676
The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary files by constructing a (1) symlink or (2) hard link, a different vulnerability than CVE-2012-3485.... Read more
Affected Products : tunnelblick- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2006-3118
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary f... Read more
Affected Products : spread- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-4415
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a d... Read more
Affected Products : http_server- Published: Nov. 08, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2016-0431
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0419.... Read more
Affected Products : solaris- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2004-0814
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attack... Read more
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-4028
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled differently if the file exists.... Read more
Affected Products : x_server- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2001-0119
getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-2678
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#pas... Read more
- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025