Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2005-03-01 CVE-2004-1032 fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly append the intended fcrontab.sig to the resulting string.
local
low complexity
thibault-godouet gentoo
2.1
2005-03-01 CVE-2004-1030 Local vulnerability in Fcron FCronTab/FCronSighUp
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message.
local
low complexity
thibault-godouet gentoo
2.1
2005-02-28 CVE-2005-0625 Information Disclosure vulnerability in Debian Reportbug 2.60/2.61/3.2
reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.
local
low complexity
debian
2.1
2005-02-28 CVE-2005-0624 Local Security vulnerability in Debian Reportbug 2.60/2.61
reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.
local
low complexity
debian
2.1
2005-02-28 CVE-2005-0619 Information Disclosure vulnerability in Einstein
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.
local
low complexity
bfriendly-com
2.1
2005-02-25 CVE-2005-0580 Local Security vulnerability in Cmd5Checkpw 0.20/0.21/0.22
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.
local
low complexity
krzysztof-dabrowski
2.1
2005-02-23 CVE-2005-0521 SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.
local
low complexity
sendlink
2.1
2005-02-23 CVE-2005-0518 Information Disclosure vulnerability in Exeem 0.21
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.
local
low complexity
exeem
2.1
2005-02-23 CVE-2005-0517 Unspecified vulnerability in Peerftp 5 Peerftp 5
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.
local
low complexity
peerftp-5
2.1
2005-02-23 CVE-2004-0481 Unspecified vulnerability in SUN Solaris and Sunos
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
local
low complexity
sun
2.1