Latest CVE Feed
-
1.2
LOWCVE-2006-4232
Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.... Read more
Affected Products : globus_toolkit- Published: Aug. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-3551
NCP Secure Enterprise Client (aka VPN/PKI client) 8.30 Build 59, and possibly earlier versions, when the Link Firewall and Personal Firewall are both configured to block all inbound and outbound network traffic, allows context-dependent attackers to send ... Read more
Affected Products : secure_client- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2013-6891
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.... Read more
- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2012-0645
Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice commands, which allows physically proximate attackers to bypass the locked state via a command that forwards an active e-mail message to an arbitrary recipient... Read more
Affected Products : iphone_os- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2002-2001
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2008-5450
Unspecified vulnerability in the Oracle Applications Platform Engineering component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows local users to affect confidentiality via unknown vectors.... Read more
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2014-3537
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.... Read more
- Published: Jul. 23, 2014
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2010-3718
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demo... Read more
Affected Products : tomcat- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2005-4660
Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted... Read more
Affected Products : ipcop- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-3118
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary f... Read more
Affected Products : spread- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-4676
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file.... Read more
Affected Products : rendezvous- Published: Sep. 11, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-1999-0371
Lynx allows a local user to overwrite sensitive files through /tmp symlinks.... Read more
Affected Products : lynx- Published: Feb. 11, 1999
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0887
xSANE 0.81 and earlier allows local users to modify files of other xSANE users via a symlink attack on temporary files.... Read more
- Published: Jan. 15, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-1999-0475
A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.... Read more
Affected Products : procmail- Published: Apr. 05, 1999
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-0741
Linux kernel before 2.6.15.5, when running on Intel processors, allows local users to cause a denial of service ("endless recursive fault") via unknown attack vectors related to a "bad elf entry address."... Read more
Affected Products : linux_kernel- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-6095
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.... Read more
Affected Products : proftpd- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-2724
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of ... Read more
Affected Products : samba- Published: Sep. 06, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2015-4822
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2015-4831.... Read more
Affected Products : solaris- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2006-5757
Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data s... Read more
Affected Products : linux_kernel- Published: Nov. 06, 2006
- Modified: Apr. 09, 2025