Latest CVE Feed
-
2.1
LOWCVE-2015-3010
ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.... Read more
Affected Products : ceph-deploy- EPSS Score: %0.05
- Published: Jun. 16, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0199
The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allows local users to obtain sensitive information by reading... Read more
Affected Products : rhevm-reports- EPSS Score: %0.06
- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-5191
The syslog implementation in Apple Mac OS X before 10.9 allows local users to obtain sensitive information by leveraging access to the Guest account and reading console-log messages from previous Guest sessions.... Read more
- EPSS Score: %0.13
- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-4407
XRunSabre in sabre (aka xsabre) 0.2.4b relies on the ability to create /tmp/sabre.log, which allows local users to cause a denial of service (application unavailability) by creating a /tmp/sabre.log file that cannot be overwritten.... Read more
Affected Products : xsabre- EPSS Score: %0.05
- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2000-0461
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.... Read more
- EPSS Score: %0.08
- Published: May. 29, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-6987
The File Bookmark component in Apple OS X before 10.11.1 allows local users to cause a denial of service (application crash) via crafted bookmark metadata in a folder.... Read more
- EPSS Score: %0.04
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2003-0476
The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-5870
The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.... Read more
- EPSS Score: %0.08
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-0200
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.... Read more
Affected Products : websphere_commerce- EPSS Score: %0.06
- Published: May. 29, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-8025
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.... Read more
- EPSS Score: %0.07
- Published: Nov. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-5174
The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a b... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2018-2575
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, and 12.2.0.1. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with network ac... Read more
- EPSS Score: %0.23
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
2.1
LOWCVE-2013-1030
mdmclient in Mobile Device Management in Apple Mac OS X before 10.8.5 places a password on the command line, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : mac_os_x- EPSS Score: %0.13
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-8133
arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanis... Read more
Affected Products : linux_kernel- EPSS Score: %0.04
- Published: Dec. 17, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-3276
The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.... Read more
- EPSS Score: %0.11
- Published: Oct. 21, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-5325
Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect plugin 1.0.01 and earlier for WordPress allow remote authenticated users with certain permissions to inject arbitrary web script or HT... Read more
- EPSS Score: %0.11
- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4820
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.... Read more
- EPSS Score: %0.19
- Published: Sep. 23, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-4377
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with the "create petition" permission to inject arbitrary web script or HTML via unknow... Read more
Affected Products : petition- EPSS Score: %0.21
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-1998
Cross-site scripting (XSS) vulnerability in the CCK TableField module 6.x before 6.x-1.2 for Drupal allows remote authenticated users, with certain node creation or editing privileges, to inject arbitrary web script or HTML via table headers.... Read more
- EPSS Score: %0.34
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-1050
Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information i... Read more
Affected Products : kwik-pay_payroll- EPSS Score: %0.03
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025