Search

Found 1,351 results in 141ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2011-0542 low 3.3 FIX debian debian fuse 15y ago fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
CVE-2011-0541 low 3.3 FIX debian debian fuse 15y ago fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
CVE-2011-1781 low 1.2 FIX debian debian systemtap 15y ago SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that a…
CVE-2011-1769 low 1.2 FIX debian debian systemtap 15y ago SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expres…
CVE-2011-3266 low 2.6 FIX debian debian wireshark 15y ago The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of servic…
CVE-2011-3262 low 2.1 FIX debian debian citrix 15y ago tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via uns…
CVE-2011-2642 low 2.6 FIX debian debian phpmyadmin 15y ago Multiple cross-site scripting (XSS) vulnerabilities in the table Print view implementation in tbl_printview.php in phpMyAdmin before 3.3.10.3 and 3.4.x before 3.4.3.2 allow remote authenticated users…
CVE-2011-2694 low 2.6 FIX ubuntu ubuntudebian debian samba 15y ago Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to …
CVE-2011-2300 low 3.7 FIX debian debian oracle 15y ago Unspecified vulnerability in Oracle VM VirtualBox 3.0, 3.1, 3.2, and 4.0 through 4.0.8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Guest A…
CVE-2011-2465 low 2.6 FIX debian debian isc 15y ago Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote att…
CVE-2009-5082 low 3.3 FIX debian debian gnu 15y ago The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes i…
CVE-2009-5081 low 3.3 FIX debian debian gnu 15y ago The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the te…
CVE-2009-5080 low 3.3 FIX debian debian gnu 15y ago The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scripts in GNU troff (aka groff) 1.21 and earlier do not properly handle certain f…
CVE-2009-5079 low 3.3 FIX debian debian gnu 15y ago The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack …
CVE-2009-5044 low 3.3 FIX debian debianmacos macos gnu 15y ago contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
CVE-2011-2533 low 3.3 FIX debian debian freedesktop 15y ago The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
CVE-2011-1943 low 2.1 FIX fedora fedoradebian debian gnome 15y ago The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows …
CVE-2011-2146 low 2.1 FIX debian debian vmware 15y ago mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.1.x before 3.1.3, VMware ESXi 3.5 through 4.1, and…
CVE-2011-1945 low 2.6 FIX debian debian openssl 15y ago The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly …
CVE-2011-1486 low 3.3 FIX debian debian redhat 15y ago libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same …
CVE-2011-1758 low 3.7 FIX debian debian fedoraproject 15y ago The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured,…
CVE-2011-1784 low 3.6 FIX debian debian keepalived 15y ago The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.pid, and (3) vrrp.pid files in /var/run/, which allows loca…
CVE-2011-0995 low 2.1 FIX debian debian rubyforge 15y ago The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges v…
CVE-2011-0905 low 3.5 FIX debian debian david_king 15y ago The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when tight encodin…
CVE-2011-0904 low 3.5 FIX debian debian david_king 15y ago The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding …
CVE-2011-1499 low 2.6 FIX debian debian banu 15y ago acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the orig…
CVE-2011-1580 low 3.5 FIX debian debian mediawiki 15y ago The transwiki import functionality in MediaWiki before 1.16.3 does not properly check privileges, which allows remote authenticated users to perform imports from any wgImportSources wiki via a crafte…
CVE-2010-2788 low 2.6 FIX debian debian mediawiki 15y ago Cross-site scripting (XSS) vulnerability in profileinfo.php in MediaWiki before 1.15.5, when wgEnableProfileInfo is enabled, allows remote attackers to inject arbitrary web script or HTML via the fil…
CVE-2011-1500 low 2.1 FIX debian debian kevinmehall 15y ago PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user's home directory, which allows local users to obtain Pandora credentials by…
CVE-2011-1401 low 3.5 FIX debian debian ikiwiki 15y ago ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-…
CVE-2011-1681 low 3.3 FIX debian debian vmware 15y ago vmware-hgfsmounter in VMware Open Virtual Machine Tools (aka open-vm-tools) 8.4.2-261024 and earlier attempts to append to the /etc/mtab file without first checking whether resource limits would inte…
CVE-2011-1678 low 3.3 FIX debian debian samba 15y ago smbfs in Samba 3.5.8 and earlier attempts to use (1) mount.cifs to append to the /etc/mtab file and (2) umount.cifs to append to the /etc/mtab.tmp file without first checking whether resource limits …
CVE-2011-1675 low 3.3 FIX debian debian linux 15y ago mount in util-linux 2.19 and earlier attempts to append to the /etc/mtab.tmp file without first checking whether resource limits would interfere, which allows local users to trigger corruption of the…
CVE-2011-1089 low 3.3 FIX debian debian gnu 15y ago The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local u…
CVE-2011-1491 low 3.5 FIX debian debian roundcube 15y ago The login form in Roundcube Webmail before 0.5.1 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensit…
CVE-2011-1155 low 1.9 FIX debian debian gentoo 15y ago The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash…
CVE-2011-1098 low 1.9 FIX debian debian gentoo 15y ago Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place.
CVE-2011-0728 low 3.5 FIX debian debian michael_hudson-doyle 15y ago Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not prop…
CVE-2011-1022 low 2.1 FIX debian debian balbir_singh 15y ago The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages or…
CVE-2010-4762 low 3.5 FIX debian debian otrs 15y ago Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or …
CVE-2010-4760 low 3.5 FIX debian debian otrs 15y ago Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain …
CVE-2010-4758 low 1.9 FIX debian debian otrs 15y ago installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier f…
CVE-2009-5056 low 2.1 FIX debian debian otrs 15y ago Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrict…
CVE-2009-5055 low 3.5 FIX debian debian otrs 15y ago Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access …
CVE-2011-0700 low 3.5 FIX debian debian wordpress 15y ago Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.0.5 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (1) the Quick/Bulk Edit ti…
CVE-2011-1074 low 1.9 FIX debian debianfreebsd freebsd 16y ago crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a directory traversal…
CVE-2011-1073 low 1.9 FIX debian debianmacos macosfreebsd freebsd 16y ago crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perfor…
CVE-2011-1031 low 3.3 FIX debian debian feh_project 16y ago The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to create arbitrary files via a symlink attack on a /tmp/feh_ temporary file, a different vulnerability t…
CVE-2011-0702 low 3.3 FIX debian debian feh_project 16y ago The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to overwrite arbitrary files via a symlink attack on a /tmp/feh_ temporary file.
CVE-2010-4341 low 2.1 FIX debian debian fedorahostedfedoraproject 16y ago The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login…
CVE-2010-3431 low 1.9 FIX debian debian linux-pam 16y ago The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local use…
CVE-2010-3316 low 3.3 FIX debian debian linux-pam 16y ago The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might a…
CVE-2010-4071 low 2.6 FIX debian debian otrs 16y ago Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an H…
CVE-2010-3586 low 3.6 FIX debian debian 16y ago Unspecified vulnerability in Oracle Solaris 9 allows local users to affect confidentiality and integrity via unknown vectors related to XScreenSaver.
CVE-2011-0016 low 2.1 FIX debian debian tor 16y ago Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memo…
CVE-2011-0007 low 3.3 FIX debian debian troglobit 16y ago pimd 2.1.5 and possibly earlier versions allows user-assisted local users to overwrite arbitrary files via a symlink attack on (1) pimd.dump when a USR1 signal is sent, or (2) pimd.cache when USR2 is…
CVE-2010-4644 low 3.5 FIX debian debian apache 16y ago Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the bla…
CVE-2010-3877 low 1.9 FIX linux-kerneldebian debian 16y ago The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from ker…
CVE-2010-3876 low 1.9 FIX linux-kernelsuse susedebian debian 16y ago net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel s…
CVE-2010-3875 low 2.1 FIX linux-kerneldebian debian 16y ago The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information fro…
CVE-2010-4352 low 2.1 FIX debian debian d-bus_project 16y ago Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.
CVE-2010-3850 low 3.1 EXPFIX linux-kernelsuse susedebian debian 16y ago The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions …
CVE-2010-4171 low 2.1 FIX slesdebian debian systemtap 16y ago The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unloading of arbitrary ker…
CVE-2010-4021 low 2.1 FIX debian debian mit 16y ago The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to imp…
CVE-2010-1324 low 3.7 3.7 FIX debian debian mit 16y ago MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain privileges, or have un…
CVE-2010-1323 low 3.7 3.7 FIX debian debian mit 16y ago MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to modify user-visi…
CVE-2010-4083 low 1.9 FIX linux-kernelsuse susedebian debian 16y ago The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kerne…
CVE-2010-4081 low 1.9 FIX linux-kernelsuse susedebian debian 16y ago The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive…
CVE-2010-4080 low 2.1 FIX linux-kernelsuse susedebian debian 16y ago The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive i…
CVE-2010-4079 low 1.9 FIX linux-kerneldebian debian 16y ago The ivtvfb_ioctl function in drivers/media/video/ivtv/ivtvfb.c in the Linux kernel before 2.6.36-rc8 does not properly initialize a certain structure member, which allows local users to obtain potent…
CVE-2010-4078 low 1.9 FIX linux-kernelsuse susedebian debian 16y ago The sisfb_ioctl function in drivers/video/sis/sis_main.c in the Linux kernel before 2.6.36-rc6 does not properly initialize a certain structure member, which allows local users to obtain potentially …
CVE-2010-4074 low 1.9 FIX linux-kerneldebian debian 16y ago The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack …
CVE-2010-4073 low 2.9 EXPFIX linux-kernelsuse susedebian debian 16y ago The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vecto…
CVE-2010-4072 low 1.9 FIX linux-kernelsuse susedebian debian 16y ago The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from k…
CVE-2010-3779 low 3.5 FIX debian debian dovecot 16y ago Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass inten…
CVE-2010-3298 low 2.1 FIX ubuntu ubuntususe suse linux-kernel 16y ago The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensi…
CVE-2010-3297 low 2.1 FIX ubuntu ubuntususe suse linux-kernel 16y ago The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensit…
CVE-2010-3296 low 2.1 FIX ubuntu ubuntususe suse linux-kernel 16y ago The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain p…
CVE-2010-3310 low 1.9 ubuntu ubuntu linux-kerneldebian debian 16y ago Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have u…
CVE-2010-3477 low 2.1 FIX linux-kernelubuntu ubuntudebian debian 16y ago The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certa…
CVE-2010-2080 low 3.5 FIX debian debian otrs 16y ago Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 allow remote authenticated users to inject arbitrary web script or H…
CVE-2010-3074 low 2.1 FIX debian debian arg0 16y ago SSL_Cipher.cpp in EncFS before 1.7.0 uses an improper combination of an AES cipher and a CBC cipher mode for encrypted filesystems, which allows local users to obtain sensitive information via a wate…
CVE-2010-3073 low 3.1 EXPFIX debian debian arg0 16y ago SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users …
CVE-2010-2803 low 1.9 FIX linux-kerneldebian debiansuse suse 16y ago The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.…
CVE-2010-2226 low 2.1 FIX linux-kerneldebian debianubuntu ubuntu 16y ago The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write a…
CVE-2010-1172 low 3.6 FIX debian debian freedesktop 16y ago DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying propertie…
CVE-2008-7258 low 3.1 EXP debian debian anibal_monsalve_salaz 16y ago The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins wit…
CVE-2010-2242 low 2.1 FIX debian debian libvirt 16y ago Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP addre…
CVE-2009-4269 low 2.1 FIX debian debian apache 16y ago Use of Password Hash With Insufficient Computational Effort in Apache Derby
CVE-2010-2539 low 2.1 FIX debian debian osgeoumn 16y ago Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of tempor…
CVE-2010-0213 low 2.6 FIX debian debian isc 16y ago BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of ser…
CVE-2010-2056 low 3.3 FIX debian debian gnu 16y ago GNU gv before 3.7.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
CVE-2010-2431 low 2.6 FIX debian debian apple 16y ago The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cach…
CVE-2010-2322 low 2.6 FIX slesdebian debian matthias_klose 16y ago Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .…
CVE-2010-2192 low 1.9 FIX debian debian vincent_fourmond 16y ago The make_lockdir_name function in policy.c in pmount 0.9.18 allow local users to overwrite arbitrary files via a symlink attack on a file in /var/lock/.
CVE-2009-4901 low 2.1 FIX debian debian muscle 16y ago The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) vi…
CVE-2010-2286 low 3.3 FIX debian debian wireshark 16y ago The SigComp Universal Decompressor Virtual Machine dissector in Wireshark 0.10.7 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (infinite loop) via unknow…
CVE-2010-2285 low 3.3 FIX debian debian wireshark 16y ago The SMB PIPE dissector in Wireshark 0.8.20 through 1.0.13 and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
CVE-2010-2283 low 3.3 FIX debian debian wireshark 16y ago The SMB dissector in Wireshark 0.99.6 through 1.0.13, and 1.2.0 through 1.2.8 allows remote attackers to cause a denial of service (NULL pointer dereference) via unknown vectors.
CVE-2010-2058 low 2.1 FIX debian debian prelude-technologies 16y ago setup.py in Prewikka 0.9.14 installs prewikka.conf with world-readable permissions, which allows local users to obtain the SQL database password.