Latest CVE Feed
-
2.1
LOWCVE-2008-1033
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment var... Read more
- EPSS Score: %0.20
- Published: Jun. 02, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-3612
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive i... Read more
- EPSS Score: %0.07
- Published: Oct. 19, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-2089
The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a M... Read more
Affected Products : websphere_application_server- EPSS Score: %0.21
- Published: Aug. 13, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-0456
The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.... Read more
- EPSS Score: %0.07
- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-1426
Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.... Read more
- EPSS Score: %0.06
- Published: Feb. 23, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-0146
IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which al... Read more
Affected Products : content_collector- EPSS Score: %0.05
- Published: Mar. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2008-2101
The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.... Read more
- EPSS Score: %0.06
- Published: Sep. 03, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-3875
The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structur... Read more
- EPSS Score: %0.07
- Published: Jan. 03, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-1952
The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of service (crash) by mapping an arbitrary amount of guest memory.... Read more
Affected Products : xen_para_virtualized_frame_buffer- EPSS Score: %0.08
- Published: Jun. 23, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-3789
Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.... Read more
Affected Products : samba- EPSS Score: %1.10
- Published: Aug. 27, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-0491
The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.... Read more
Affected Products : enterprise_linux- EPSS Score: %0.09
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0388
The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : mysql- EPSS Score: %0.11
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0415
Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.... Read more
- EPSS Score: %0.30
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-5371
The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via standar... Read more
Affected Products : tivoli_storage_manager- EPSS Score: %0.04
- Published: Jan. 23, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-1595
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information b... Read more
- EPSS Score: %0.08
- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-0824
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDialer log files.... Read more
Affected Products : mac_os_x- EPSS Score: %0.32
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-0206
Array index error in the aio_read_events_ring function in fs/aio.c in the Linux kernel through 3.15.1 allows local users to obtain sensitive information from kernel memory via a large head value.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jun. 25, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0189
virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file.... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation virt-who- EPSS Score: %0.07
- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-1000
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.... Read more
Affected Products : lintian- EPSS Score: %0.06
- Published: Jan. 10, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0564
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT... Read more
- EPSS Score: %0.07
- Published: Dec. 23, 2004
- Modified: Apr. 03, 2025