Show filters
99 Total Results
Displaying 21-30 of 99
Sort by:
Attacker Value
Unknown
CVE-2011-4092
Disclosure Date: February 10, 2014 (last updated October 05, 2023)
obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.
0
Attacker Value
Unknown
CVE-2011-4613
Disclosure Date: February 05, 2014 (last updated October 05, 2023)
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.
0
Attacker Value
Unknown
CVE-2013-1066
Disclosure Date: October 03, 2013 (last updated October 05, 2023)
language-selector 0.110.x before 0.110.1, 0.90.x before 0.90.1, and 0.79.x before 0.79.4 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
0
Attacker Value
Unknown
CVE-2011-1842
Disclosure Date: May 03, 2011 (last updated October 04, 2023)
dbus_backend/lsd.py in the D-Bus backend in language-selector before 0.6.7 does not validate the arguments to the (1) SetSystemDefaultLangEnv and (2) SetSystemDefaultLanguageEnv functions, which allows local users to gain privileges via shell metacharacters in a string argument, a different vulnerability than CVE-2011-0729.
0
Attacker Value
Unknown
CVE-2011-0729
Disclosure Date: April 29, 2011 (last updated October 04, 2023)
dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result, which allows local users to modify the /etc/default/locale and /etc/environment files via a (1) SetSystemDefaultLangEnv or (2) SetSystemDefaultLanguageEnv call.
0
Attacker Value
Unknown
CVE-2011-0724
Disclosure Date: February 19, 2011 (last updated October 04, 2023)
The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key, which allows remote attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2010-0834
Disclosure Date: August 10, 2010 (last updated October 04, 2023)
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.
0
Attacker Value
Unknown
CVE-2009-1296
Disclosure Date: June 09, 2009 (last updated October 04, 2023)
The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk. NOTE: the log files are only readable by root.
0
Attacker Value
Unknown
CVE-2009-1601
Disclosure Date: May 11, 2009 (last updated October 04, 2023)
The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local users to bypass intended access restrictions via read or write operations involving this directory.
0
Attacker Value
Unknown
CVE-2008-6792
Disclosure Date: May 07, 2009 (last updated October 04, 2023)
system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES and consequently limits effective password lengths to eight characters, which makes it easier for context-dependent attackers to successfully conduct brute-force password attacks.
0