Latest CVE Feed
-
2.1
LOWCVE-2015-1087
Directory traversal vulnerability in Backup in Apple iOS before 8.3 allows attackers to read arbitrary files via a crafted relative path.... Read more
Affected Products : iphone_os- EPSS Score: %0.05
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1142
LaunchServices in Apple OS X before 10.10.3 allows local users to cause a denial of service (Finder crash) via crafted localization data.... Read more
- EPSS Score: %0.06
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-8482
Blue Coat Unified Agent before 4.6.2 does not prevent modification of its configuration files when running in local enforcement mode, which allows local administrators to unblock categories or disable the agent via unspecified vectors.... Read more
Affected Products : unified_agent- EPSS Score: %0.06
- Published: Dec. 07, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-8135
The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in a "vi... Read more
Affected Products : libvirt- EPSS Score: %0.16
- Published: Dec. 19, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-0094
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the availabil... Read more
- EPSS Score: %2.67
- Published: Mar. 11, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-7000
Notification Center in Apple iOS before 9.1 mishandles changes to "Show on Lock Screen" settings, which allows physically proximate attackers to obtain sensitive information by looking for a (1) Phone or (2) Messages notification on the lock screen soon a... Read more
Affected Products : iphone_os- EPSS Score: %0.07
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-0084
The Task Scheduler in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to bypass intended r... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_8 windows_rt- EPSS Score: %1.22
- Published: Mar. 11, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1677
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR p... Read more
- EPSS Score: %3.16
- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-2714
Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonst... Read more
- EPSS Score: %0.10
- Published: May. 14, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5901
The Secure Empty Trash feature in Finder in Apple OS X before 10.11 improperly deletes Trash files, which might allow local users to obtain sensitive information by reading storage media, as demonstrated by reading a flash drive.... Read more
- EPSS Score: %0.06
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-6488
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform: 10.2.0.5, 11.1.0.1 EM DB Control: 11.1.0.7, 11.2.0.3, 11.2.0.4 EM Plugin for DB: 12.1.0.4, 12.1.0.5, and 12.1.0.6... Read more
Affected Products : enterprise_manager enterprise_manager_grid_control enterprise_manager_database_control- EPSS Score: %0.19
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-3757
Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.... Read more
- EPSS Score: %0.05
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-7067
IOThunderboltFamily in Apple OS X before 10.11.2 allows local users to cause a denial of service (NULL pointer dereference) via an unspecified userclient type.... Read more
- EPSS Score: %0.06
- Published: Dec. 11, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1415
The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the fil... Read more
Affected Products : freebsd- EPSS Score: %0.04
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5893
SMBClient in SMB in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.... Read more
- EPSS Score: %0.06
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1676
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR p... Read more
- EPSS Score: %3.16
- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-4817
The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attackers to bypass intended access restrictions and replace file backups by using a certain backup option in conjunction with a filename tha... Read more
Affected Products : tivoli_storage_manager- EPSS Score: %0.15
- Published: Nov. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5240
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted... Read more
- EPSS Score: %0.33
- Published: Aug. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0164
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by rea... Read more
- EPSS Score: %0.04
- Published: May. 05, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-2013
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : python-keystoneclient- EPSS Score: %0.06
- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025