Latest CVE Feed
-
2.1
LOWCVE-2015-3245
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline c... Read more
Affected Products : libuser- EPSS Score: %15.42
- Published: Aug. 11, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5851
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.... Read more
- EPSS Score: %0.06
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-4357
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.... Read more
- EPSS Score: %0.08
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-4910
Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.... Read more
- EPSS Score: %0.51
- Published: Oct. 22, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-2030
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as de... Read more
- EPSS Score: %0.04
- Published: Dec. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-2851
smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.... Read more
Affected Products : smb4k- EPSS Score: %0.08
- Published: Sep. 08, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3341
DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh.... Read more
Affected Products : dns_package- EPSS Score: %0.07
- Published: Dec. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-4190
Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a .. (dot dot) in the name parameter for a modload operation.... Read more
Affected Products : autohtml_module- EPSS Score: %0.15
- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-8133
arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanis... Read more
Affected Products : linux_kernel- EPSS Score: %0.04
- Published: Dec. 17, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2009-4145
nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to ... Read more
Affected Products : networkmanager- EPSS Score: %0.06
- Published: Dec. 23, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-2918
The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size of ... Read more
Affected Products : thegreenbow_vpn_client- EPSS Score: %0.16
- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2003-0476
The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-0124
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : employee_timeclock_software- EPSS Score: %0.06
- Published: Mar. 15, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-1292
UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0.1.x before 7.0.1.4, and 7.1.x before 7.1.0.1 on Linux and AIX places a username and password on the command line, which allows local users to obtain credentials by listing the process.... Read more
- EPSS Score: %0.05
- Published: Apr. 14, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-4380
MySQL before 4.1.13 allows local users to cause a denial of service (persistent replication slave crash) via a query with multiupdate and subselects.... Read more
Affected Products : mysql- EPSS Score: %0.07
- Published: Aug. 28, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-5061
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.14 services for Lotus Domino, when Domino Native Authentication is enabled, might allow remote authenticated users to cause a denial of service (daemon crash) by going offline, aka SPR MLZG7UP... Read more
- EPSS Score: %0.57
- Published: Mar. 22, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-2899
The monitor perl script in the Sybase database plug-in in SpringSource Hyperic HQ before 4.3 allows local users to obtain the database password by listing the process and its arguments.... Read more
Affected Products : hyperic_hq- EPSS Score: %0.04
- Published: Dec. 05, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-4031
MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.... Read more
- EPSS Score: %0.26
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-4829
Cross-site scripting (XSS) vulnerability in the Automated Logout module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users with administer autologout privileges to inject arbitrary web script or HTML via unspeci... Read more
- EPSS Score: %0.34
- Published: Apr. 27, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-1435
NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : officescan- EPSS Score: %0.45
- Published: Apr. 27, 2009
- Modified: Apr. 09, 2025