NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
36620 | CVE-2013-0266 | manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files. | 2 | 2.1 | Low | 2017-01-18 | 2013-03-18 | View | |
43532 | CVE-2012-1660 | Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script or HTML via vectors related to (1) checkboxes or (2) radios. | 2 | 2.1 | Low | 2017-01-19 | 2012-12-20 | View | |
45836 | CVE-2012-4453 | dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information. | 2 | 2.1 | Low | 2017-01-19 | 2014-01-07 | View | |
49932 | CVE-2009-2691 | The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition. | 2 | 2.1 | Low | 2017-01-07 | 2012-03-19 | View | |
54028 | CVE-2007-1856 | Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c. | 2 | 2.1 | Low | 2017-01-07 | 2011-03-07 | View |
Page 1771 of 17672, showing 5 records out of 88360 total, starting on record 8851, ending on 8855