Filtered by CWE-264
Total 5465 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2008-0931 2 Debian, Xwine 2 Debian Linux, Xwine 2008-09-05 N/A
w_export.c in XWine 1.0.1 on Debian GNU/Linux sets insecure permissions (0666) for /etc/wine/config, which might allow local users to execute arbitrary commands or cause a denial of service by modifying the file.
CVE-2008-0162 2 Debian, Sam Lantinga 2 Debian Linux, Splitvt 2008-09-05 N/A
misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.
CVE-2007-4669 1 Firebirdsql 1 Firebird 2008-09-05 N/A
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.
CVE-2006-6662 1 Suse 3 Linux Enterprise Desktop, Suse Linux, Suse Open Enterprise Server 2008-09-05 N/A
Unspecified vulnerability in Linux User Management (novell-lum) on SUSE Linux Enterprise Desktop 10 and Open Enterprise Server 9, under unspecified conditions, allows local users to log in to the console without a password.
CVE-2004-0041 1 Mod Auth Shadow 1 Mod Auth Shadow 2008-09-05 N/A
The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.