Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2004-12-31 CVE-2004-1387 Local Security vulnerability in Apache Http Server 1.3.31
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
local
low complexity
apache
2.1
2004-12-31 CVE-2004-1382 Local Security vulnerability in glibc
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
local
low complexity
gnu
2.1
2004-12-31 CVE-2004-1296 Local Security vulnerability in groff
The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
local
low complexity
gnu
2.1
2004-12-31 CVE-2004-1179 Local Insecure Temporary File Creation vulnerability in Debian Debmake
The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files via a symlink attack on temporary directories.
local
low complexity
debian
2.1
2004-12-31 CVE-2004-0999 Remote Memory Corruption vulnerability in ZGV Image Viewer Animated GIF
zgv 5.5.3 allows remote attackers to cause a denial of service (application crash via segmentation fault) via crafted multiple-image (animated) GIF images.
network
high complexity
zgv
2.6
2004-12-31 CVE-2004-0824 Symbolic Link vulnerability in Apple PPPDialer Insecure Log File Creation
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.
local
low complexity
apple
2.1
2004-12-31 CVE-2004-0813 Unspecified vulnerability in Ide-Cd
Unknown vulnerability in the SG_IO functionality in ide-cd allows local users to bypass read-only access and perform unauthorized write and erase operations.
local
low complexity
ide-cd
2.1
2004-12-31 CVE-2004-0533 Unspecified vulnerability in Businessobjects Infoview and Webintelligence
Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.
local
low complexity
businessobjects
2.1
2004-12-31 CVE-2004-0491 Local MEMLOCK RLIMIT Bypass Denial Of Service vulnerability in Redhat Enterprise Linux 3.0
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.
local
low complexity
redhat
2.1
2004-12-31 CVE-2004-0462 The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server.
local
low complexity
2.1