Latest CVE Feed
-
2.1
LOWCVE-2014-3209
The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.... Read more
Affected Products : ldns- EPSS Score: %0.15
- Published: Nov. 16, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-0972
The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.... Read more
- EPSS Score: %0.08
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0971
The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.... Read more
Affected Products : kerberos_5- EPSS Score: %0.11
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-3532
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then e... Read more
- EPSS Score: %0.12
- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0181
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations... Read more
- EPSS Score: %0.03
- Published: Apr. 27, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9585
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end o... Read more
- EPSS Score: %0.04
- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-0968
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.... Read more
- EPSS Score: %0.07
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0813
Unknown vulnerability in the SG_IO functionality in ide-cd allows local users to bypass read-only access and perform unauthorized write and erase operations.... Read more
Affected Products : ide-cd- EPSS Score: %0.13
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-3533
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.... Read more
- EPSS Score: %0.08
- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-0797
The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash).... Read more
Affected Products : zlib- EPSS Score: %0.76
- Published: Oct. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-3615
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.... Read more
- EPSS Score: %0.09
- Published: Nov. 01, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-3640
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket... Read more
- EPSS Score: %0.06
- Published: Nov. 07, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2009-4901
The MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 might allow local users to cause a denial of service (daemon crash) via crafted SCARD_SET_ATTRIB message data, which is improp... Read more
Affected Products : pcsc-lite- EPSS Score: %0.07
- Published: Jun. 18, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-1044
The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors tha... Read more
- EPSS Score: %0.06
- Published: Feb. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-1080
The do_replace function in net/bridge/netfilter/ebtables.c in the Linux kernel before 2.6.39 does not ensure that a certain name field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memor... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Jun. 21, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-0547
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a craft... Read more
Affected Products : samba- EPSS Score: %1.29
- Published: Feb. 04, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-4870
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.... Read more
- EPSS Score: %0.04
- Published: Nov. 01, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-0424
talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.... Read more
Affected Products : communicator- EPSS Score: %0.12
- Published: Mar. 18, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-1322
QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.... Read more
- EPSS Score: %0.11
- Published: May. 02, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-5004
Unspecified vulnerability in the rdist command in IBM AIX 5.2.0 and 5.3.0 allows local users to overwrite arbitrary files via unspecified vectors.... Read more
Affected Products : aix- EPSS Score: %0.06
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025