CVE-2022-1804
- EPSS 0.02%
- Published 25.03.2025 12:28:08
- Last modified 26.08.2025 17:13:47
accountsservice no longer drops permissions when writting .pam_environment
CVE-2011-4613
- EPSS 0.08%
- Published 05.02.2014 19:55:28
- Last modified 11.04.2025 00:51:21
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misint...
CVE-2009-1601
- EPSS 0.14%
- Published 11.05.2009 15:30:00
- Last modified 09.04.2025 00:30:58
The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local users to bypass intended access restrictions via rea...
- EPSS 0.38%
- Published 07.05.2009 17:30:03
- Last modified 09.04.2025 00:30:58
system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES and consequently limits effective password lengths to eight characters, which makes it easier for co...
CVE-2009-1573
- EPSS 0.07%
- Published 06.05.2009 17:30:09
- Last modified 09.04.2025 00:30:58
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
CVE-2008-4306
- EPSS 6.09%
- Published 04.11.2008 21:00:01
- Last modified 09.04.2025 00:30:58
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.