Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2005-02-09 CVE-2004-0968 The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
local
low complexity
gnu redhat
2.1
2005-02-09 CVE-2004-0966 Insecure Temporary File Creation vulnerability in GNU GetText
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
local
low complexity
gnu ubuntu
2.1
2005-02-07 CVE-2005-0231 Unspecified vulnerability in Mozilla Firefox 1.0
Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."
network
high complexity
mozilla
2.6
2005-01-28 CVE-2005-0318 Remote vulnerability in Alt-N Webadmin 3.0.2
useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.
local
low complexity
alt-n
2.1
2005-01-27 CVE-2005-0312 Remote Denial Of Service vulnerability in WAR FTP Daemon WAR FTP Daemon 1.8/1.82Rc9
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.
local
low complexity
war-ftp-daemon
2.1
2005-01-27 CVE-2004-0923 Local Password Disclosure vulnerability in CUPS Error_Log
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.
local
low complexity
easy-software-products apple
2.1
2005-01-27 CVE-2004-0881 getmail 4.x before 4.2.0, and other versions before 3.2.5, when run as root, allows local users to write files in arbitrary directories via a symlink attack on subdirectories in the maildir.
local
low complexity
getmail gentoo slackware
2.1
2005-01-27 CVE-2004-0880 getmail 4.x before 4.2.0, when run as root, allows local users to overwrite arbitrary files via a symlink attack on an mbox file.
local
high complexity
getmail gentoo slackware
1.2
2005-01-26 CVE-2004-1340 Unspecified vulnerability in Debian Linux 3.0
Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.
local
low complexity
debian
2.1
2005-01-24 CVE-2005-0145 Unspecified vulnerability in Mozilla Firefox
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
network
high complexity
mozilla
2.6