Latest CVE Feed
-
1.2
LOWCVE-1999-1042
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.... Read more
Affected Products : resource_manager- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-3342
noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.... Read more
Affected Products : noweb- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1333
Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerability that could allow local users to overwrite files.... Read more
Affected Products : cups- Published: May. 10, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0222
webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack.... Read more
Affected Products : webmin- Published: Mar. 26, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1301
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.... Read more
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2008-4593
Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obtain sensitive information by performing an Emergency Call tap and then reading SMS messages on the device ... Read more
Affected Products : iphone- Published: Oct. 17, 2008
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2006-6306
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.... Read more
Affected Products : client- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2015-4823
Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1.2.3 allows local users to affect confidentiality via unknown vectors related to Essbase Rapid Deploy.... Read more
Affected Products : hyperion- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2005-1066
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-1045
nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests.... Read more
Affected Products : nss_ldap- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0154
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.... Read more
Affected Products : unixware- Published: Feb. 16, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2016-0431
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2016-0419.... Read more
Affected Products : solaris- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2015-4822
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect availability via unknown vectors related to Solaris Kernel Zones, a different vulnerability than CVE-2015-4831.... Read more
Affected Products : solaris- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2006-5214
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2012-6095
ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD or (2) XMKD commands.... Read more
Affected Products : proftpd- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-5757
Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data s... Read more
Affected Products : linux_kernel- Published: Nov. 06, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2013-2217
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.... Read more
- Published: Sep. 23, 2013
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2007-3108
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.... Read more
Affected Products : openssl- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2012-2678
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#pas... Read more
- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025