Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2005-04-26 CVE-2005-1270 Local Insecure Temporary File Creation vulnerability in Rootkit Hunter
The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
local
low complexity
gentoo
2.1
2005-04-15 CVE-2005-1126 Resource Management Errors vulnerability in Freebsd
The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel memory.
local
low complexity
freebsd CWE-399
2.1
2005-04-14 CVE-2005-0124 Local Buffer Overflow vulnerability in Linux Kernel Coda_Pioctl
The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a buffer overflow.
local
low complexity
linux
2.1
2005-04-14 CVE-2004-1237 Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors.
local
low complexity
linux redhat suse
2.1
2005-04-13 CVE-2005-1301 Remote Security vulnerability in Nprotect Netizen 2005.3.17.1
nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.
network
high complexity
nprotect
2.6
2005-03-25 CVE-2005-0585 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-03-23 CVE-2005-0143 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-03-21 CVE-2005-0715 Unspecified vulnerability in Apple mac OS X and mac OS X Server
AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local users to read the contents of a Drop Box.
local
low complexity
apple
2.1
2005-03-14 CVE-2005-0510 Denial-Of-Service vulnerability in fallback-reboot
The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.
local
low complexity
fallback-reboot
2.1
2005-03-09 CVE-2005-0719 Denial Of Service vulnerability in HP Tru64 Message Queue Local
Unknown vulnerability in the systems message queue in HP Tru64 Unix 4.0F PK8 through 5.1B-2/PK4 allows local users to cause a denial of service (process crash) for processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and xntpd.
local
low complexity
hp
2.1