CVE List

Id CVE No. Status Description Phase Votes Comments Actions
22269  CVE-2006-6165  Candidate  ** DISPUTED ** ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environment.  Assigned (20061128)  None (candidate not yet proposed)    View
45116  CVE-2010-2532  Candidate  ** DISPUTED ** lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action. NOTE: there is no general agreement that this is a vulnerability, because separate control over locking can be an equally secure, or more secure, behavior in some threat environments.  Assigned (20100630)  None (candidate not yet proposed)    View
40994  CVE-2009-3559  Candidate  ** DISPUTED ** main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy.  Assigned (20091005)  None (candidate not yet proposed)    View
35151  CVE-2008-5034  Candidate  ** DISPUTED ** master-filter in printfilters-ppd 2.13 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filter.debug temporary file. NOTE: the vendor disputes this vulnerability, stating "this package does not have " possibility of attack with the help of symlinks"".  Assigned (20081110)  None (candidate not yet proposed)    View
24895  CVE-2007-1538  Candidate  ** DISPUTED ** McAfee VirusScan Enterprise 8.5.0.i uses insecure permissions for certain Windows Registry keys, which allows local users to bypass local password protection via the UIP value in (1) HKEY_LOCAL_MACHINESOFTWAREMcAfeeDesktopProtection or (2) HKEY_LOCAL_MACHINESOFTWARENetwork AssociatesTVDVirusScan EntrepriseCurrentVersion. NOTE: this issue has been disputed by third-party researchers, stating that the default permissions for HKEY_LOCAL_MACHINESOFTWARE does not allow for write access and the product does not modify the inherited permissions. There might be an interaction error with another product.  Assigned (20070320)  None (candidate not yet proposed)    View

Page 22 of 20943, showing 5 records out of 104715 total, starting on record 106, ending on 110

Actions