NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10636 | CVE-2011-4110 | The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key." | 2 | 2.1 | Low | 2017-01-07 | 2016-08-22 | View | |
| 12669 | CVE-2010-1135 | The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse. | 2 | 7.5 | High | 2017-01-18 | 2012-10-24 | View | |
| 35863 | CVE-2014-9043 | The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to bypass authentication via a null byte in the password and a valid user name, which triggers an unauthenticated bind. | 2 | 5 | Medium | 2017-01-19 | 2015-02-05 | View | |
| 44451 | CVE-2012-2737 | The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition. | 2 | 1.9 | Low | 2017-01-19 | 2012-10-30 | View | |
| 37960 | CVE-2013-1814 | The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response. | 2 | 4 | Medium | 2017-01-18 | 2013-07-03 | View |
Page 2825 of 17672, showing 5 records out of 88360 total, starting on record 14121, ending on 14125