Latest CVE Feed
-
1.2
LOWCVE-2011-3440
The Passcode Lock feature in Apple iOS before 5.0.1 on the iPad 2 does not properly implement the locked state, which allows physically proximate attackers to access data by opening a Smart Cover during power-off confirmation.... Read more
- Published: Nov. 11, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2002-2001
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0224
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.... Read more
Affected Products : unixware- Published: Feb. 15, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-1999-1042
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.... Read more
Affected Products : resource_manager- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0959
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.... Read more
Affected Products : glibc- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0140
arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.... Read more
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0222
webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack.... Read more
Affected Products : webmin- Published: Mar. 26, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0371
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.... Read more
Affected Products : kde- Published: Mar. 01, 1999
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-4232
Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.... Read more
Affected Products : globus_toolkit- Published: Aug. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-1769
SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script tha... Read more
Affected Products : systemtap- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2006-3551
NCP Secure Enterprise Client (aka VPN/PKI client) 8.30 Build 59, and possibly earlier versions, when the Link Firewall and Personal Firewall are both configured to block all inbound and outbound network traffic, allows context-dependent attackers to send ... Read more
Affected Products : secure_client- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2013-6891
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.... Read more
- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2001-0141
mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.... Read more
Affected Products : mgetty- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-1781
SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs s... Read more
Affected Products : systemtap- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2008-7256
mm/shmem.c in the Linux kernel before 2.6.28-rc8, when strict overcommit is enabled and CONFIG_SECURITY is disabled, does not properly handle the export of shmemfs objects by knfsd, which allows attackers to cause a denial of service (NULL pointer derefer... Read more
Affected Products : linux_kernel- Published: Jun. 03, 2010
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2001-0119
getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-0050
snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.... Read more
Affected Products : debian_linux- Published: Mar. 23, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2008-4593
Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obtain sensitive information by performing an Emergency Call tap and then reading SMS messages on the device ... Read more
Affected Products : iphone- Published: Oct. 17, 2008
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2001-0036
KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.... Read more
Affected Products : kth_kerberos- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1047
Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor i... Read more
Affected Products : openbsd- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025