NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
10636  CVE-2011-4110  The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."    2.1  Low  2017-01-07  2016-08-22  View
12669  CVE-2010-1135  The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.    7.5  High  2017-01-18  2012-10-24  View
35863  CVE-2014-9043  The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to bypass authentication via a null byte in the password and a valid user name, which triggers an unauthenticated bind.    Medium  2017-01-19  2015-02-05  View
44451  CVE-2012-2737  The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.    1.9  Low  2017-01-19  2012-10-30  View
37960  CVE-2013-1814  The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.    Medium  2017-01-18  2013-07-03  View

Page 2825 of 17672, showing 5 records out of 88360 total, starting on record 14121, ending on 14125

Actions