Skip to main content

Severity archive

Low severity CVEs

Low

17,964 low severity CVEs — 43,431 Critical, 125,012 High, 163,480 Medium, 17,964 Low, 2,018 Unrated across the current result set.

CVE-2005-0261

Published Feb 10, 2005

lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0966

Published Feb 9, 2005

The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allow…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0969

Published Feb 9, 2005

The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overw…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0970

Published Feb 9, 2005

The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temp…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0971

Published Feb 9, 2005

The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0976

Published Feb 9, 2005

Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary fi…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0231

Published Feb 7, 2005

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0318

Published Jan 28, 2005

useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account i…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0312

Published Jan 27, 2005

WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as de…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1340

Published Jan 26, 2005

Debian GNU/Linux 3.0 installs the libpam-radius-auth package with the pam_radius_auth.conf set to be world-readable, which allows local users to obtain sensitive information.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0072

Published Jan 24, 2005

zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0145

Published Jan 24, 2005

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download pro…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0110

Published Jan 14, 2005

Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code v…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0288

Published Jan 11, 2005

The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authentic…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0770

Published Jan 10, 2005

romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip RO…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 17,101-17,125 of 17,964 CVEsPage 685 of 719