Vulnerabilities > Robert Ancell > Lightdm > 1.0.1

DATE CVE VULNERABILITY TITLE RISK
2014-10-27 CVE-2012-1111 Information Exposure vulnerability in Robert Ancell Lightdm
lightdm before 1.0.9 does not properly close file descriptors before opening a child process, which allows local users to write to the lightdm log or have other unspecified impact.
local
low complexity
robert-ancell CWE-200
4.6
2014-05-22 CVE-2012-0943 Permissions, Privileges, and Access Controls vulnerability in multiple products
debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp.
local
low complexity
robert-ancell canonical CWE-264
2.1
2014-03-06 CVE-2011-3153 Link Following vulnerability in multiple products
dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink attack on ~/.dmrc.
1.9
2012-02-17 CVE-2011-4105 Link Following vulnerability in Robert Ancell Lightdm
LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.
1.9