Latest CVE Feed
-
2.2
LOWCVE-2025-27538
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA ... Read more
Affected Products : mattermost_server- Published: Apr. 16, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
2.2
LOWCVE-2024-21237
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileg... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
2.2
LOWCVE-2024-21243
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network acces... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
2.1
LOWCVE-2004-1333
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.... Read more
- EPSS Score: %0.23
- Published: Dec. 15, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1412
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.... Read more
Affected Products : mac_os_x- EPSS Score: %0.23
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-4285
A certain Gentoo patch for the PAM S/Key module does not properly clear credentials from memory, which allows local users to obtain sensitive information by reading system memory.... Read more
Affected Products : pam_s\/key- EPSS Score: %0.06
- Published: Apr. 28, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-1857
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.... Read more
Affected Products : web_jetadmin- EPSS Score: %78.04
- Published: Mar. 24, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-4341
The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.... Read more
- EPSS Score: %0.17
- Published: Jan. 25, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-1738
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kern... Read more
- EPSS Score: %0.03
- Published: May. 11, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-2955
The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw... Read more
- EPSS Score: %0.09
- Published: Sep. 08, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-0028
The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new... Read more
Affected Products : linux_kernel- EPSS Score: %0.22
- Published: Feb. 27, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-1335
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.... Read more
- EPSS Score: %0.19
- Published: Dec. 15, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-4959
Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browse... Read more
Affected Products : puppet_enterprise- EPSS Score: %0.06
- Published: Aug. 20, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0160
The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.... Read more
Affected Products : linux_kernel- EPSS Score: %0.23
- Published: Feb. 18, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2025-22149
JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided HTTP client's local JWK Set cache should do a full replacement when the goroutine refreshes the remote JWK Set. The current behavior is to overwrite ... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
2.1
LOWCVE-2004-1377
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
- EPSS Score: %0.07
- Published: Dec. 27, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-0622
The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have uns... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Feb. 15, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-4499
The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file.... Read more
- EPSS Score: %0.06
- Published: Jan. 30, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2009-5066
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.... Read more
- EPSS Score: %0.07
- Published: Aug. 13, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-1360
Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors.... Read more
Affected Products : iphone_os- EPSS Score: %0.08
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025