Latest CVE Feed
-
2.1
LOWCVE-2009-2910
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 proces... Read more
Affected Products : linux_kernel ubuntu_linux fedora enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_eus virtualization opensuse linux_enterprise_server +3 more products- EPSS Score: %0.05
- Published: Oct. 20, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-3861
The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with... Read more
- EPSS Score: %0.05
- Published: Dec. 10, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0059
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %0.05
- Published: Nov. 17, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0164
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by rea... Read more
- EPSS Score: %0.04
- Published: May. 05, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-2223
Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to ob... Read more
Affected Products : enterprise_virtualization_hypervisor- EPSS Score: %0.07
- Published: Jun. 24, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-6436
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference and l... Read more
Affected Products : libvirt- EPSS Score: %0.07
- Published: Jan. 07, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0710
The task_show_regs function in arch/s390/kernel/traps.c in the Linux kernel before 2.6.38-rc4-next-20110216 on the s390 platform allows local users to obtain the values of the registers of an arbitrary process by reading a status file under /proc/.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Feb. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-1356
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.19 allows local users to obtain sensitive stack-trace information via a crafted Administration Console request.... Read more
Affected Products : websphere_application_server- EPSS Score: %0.06
- Published: Jul. 19, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-2672
Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.... Read more
Affected Products : mojarra- EPSS Score: %0.06
- Published: Jun. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2013
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : python-keystoneclient- EPSS Score: %0.06
- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-1171
net/ipv4/netfilter/ip_tables.c in the IPv4 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially sen... Read more
Affected Products : linux_kernel- EPSS Score: %0.04
- Published: Jun. 22, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0685
The Delete Private Data feature in Opera before 11.01 does not properly implement the "Clear all email account passwords" option, which might allow physically proximate attackers to access an e-mail account via an unattended workstation.... Read more
Affected Products : opera_browser- EPSS Score: %0.07
- Published: Jan. 31, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2946
fs/jfs/xattr.c in the Linux kernel before 2.6.35.2 does not properly handle a certain legacy format for storage of extended attributes, which might allow local users by bypass intended xattr namespace restrictions via an "os2." substring at the beginning ... Read more
- EPSS Score: %0.07
- Published: Sep. 29, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-1940
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading password... Read more
- EPSS Score: %0.11
- Published: May. 13, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-3214
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.... Read more
Affected Products : fusion_middleware- EPSS Score: %0.83
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0016
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.... Read more
- EPSS Score: %0.06
- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2522
The mipv6 daemon in UMIP 0.4 does not verify that netlink messages originated in the kernel, which allows local users to spoof netlink socket communication via a crafted unicast message.... Read more
Affected Products : umip- EPSS Score: %0.06
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-3073
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users to obtain sensitive information by defeating cryptograph... Read more
Affected Products : encfs- EPSS Score: %0.16
- Published: Sep. 17, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2024-12706
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could allow an authenticated user to run arbitrary SQL commands on the underlying database. Thi... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
2.1
LOWCVE-2024-53698
A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify memory. We have already fixed the vulnerability in... Read more
- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Memory Corruption