Latest CVE Feed
-
2.1
LOWCVE-2012-0034
The NonManagedConnectionFactory in JBoss Enterprise Application Platform (EAP) 5.1.2 and 5.2.0, Web Platform (EWP) 5.1.2 and 5.2.0, and BRMS Platform before 5.3.1 logs the username and password in cleartext when an exception is thrown, which allows local ... Read more
- EPSS Score: %0.07
- Published: Feb. 05, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2096
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not ... Read more
- EPSS Score: %0.06
- Published: Jul. 09, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0162
The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.... Read more
Affected Products : ruby_parser- EPSS Score: %0.15
- Published: Mar. 01, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-4453
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.... Read more
Affected Products : fedora enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation dracut- EPSS Score: %0.04
- Published: Oct. 09, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-5619
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activit... Read more
Affected Products : the_sleuth_kit- EPSS Score: %0.10
- Published: Sep. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4143
The (1) checkPasswd and (2) checkGroupXlockPasswds functions in xlockmore before 5.43 do not properly handle when a NULL value is returned upon an error by the crypt or dispcrypt function as implemented in glibc 2.17 and later, which allows attackers to b... Read more
Affected Products : xlockmore- EPSS Score: %0.06
- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6394
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.... Read more
- EPSS Score: %0.06
- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-6402
base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file.... Read more
Affected Products : linux_imaging_and_printing_project- EPSS Score: %0.07
- Published: Jan. 05, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-0657
Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors.... Read more
- EPSS Score: %0.06
- Published: May. 11, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2006
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.... Read more
Affected Products : keystone- EPSS Score: %0.06
- Published: May. 21, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-5770
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.... Read more
Affected Products : mysql- EPSS Score: %0.38
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-1853
Almanah Diary 0.9.0 and 0.10.0 does not encrypt the database when closed, which allows local users to obtain sensitive information by reading the database.... Read more
Affected Products : almanah- EPSS Score: %0.06
- Published: Jan. 24, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2033
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via ... Read more
- EPSS Score: %0.18
- Published: Apr. 10, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-3223
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.0.1 allows remote authenticated users to affect confidentiality, related to BASE.... Read more
Affected Products : financial_services_software- EPSS Score: %0.22
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2403
Unspecified vulnerability in the PeopleSoft Enterprise Campus Solutions component in Oracle PeopleSoft and JDEdwards Suite Campus Solutions 9.0 Bundle #17 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
Affected Products : peoplesoft_and_jdedwards_suite_campus_solutions- EPSS Score: %0.17
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-6150
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that... Read more
Affected Products : freebsd- EPSS Score: %0.07
- Published: Nov. 30, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-1539
Cross-site scripting (XSS) vulnerability in the Workflow module 5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when used with the Token module, might allow remote authenticated users to inject arbitrary web script or HTML via a certain Comm... Read more
- EPSS Score: %0.34
- Published: Apr. 26, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-3800
XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.... Read more
Affected Products : xbmc- EPSS Score: %0.05
- Published: Aug. 07, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-0976
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained fr... Read more
Affected Products : silverstripe- EPSS Score: %0.38
- Published: Feb. 02, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-1996
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.... Read more
- EPSS Score: %0.06
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025