Latest CVE Feed
-
2.1
LOWCVE-2015-0378
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Libc.... Read more
Affected Products : solaris- EPSS Score: %0.13
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1415
The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the fil... Read more
Affected Products : freebsd- EPSS Score: %0.04
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1087
Directory traversal vulnerability in Backup in Apple iOS before 8.3 allows attackers to read arbitrary files via a crafted relative path.... Read more
Affected Products : iphone_os- EPSS Score: %0.05
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-0084
The Task Scheduler in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to bypass intended r... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_8 windows_rt- EPSS Score: %1.22
- Published: Mar. 11, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6372
The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.... Read more
Affected Products : subversion-plugin- EPSS Score: %0.06
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-3077
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.... Read more
- EPSS Score: %0.05
- Published: Sep. 15, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-3216
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.... Read more
- EPSS Score: %0.06
- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-3757
Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.... Read more
- EPSS Score: %0.05
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-2618
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors related to Input validation.... Read more
Affected Products : e-business_suite- EPSS Score: %0.15
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-0257
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files i... Read more
Affected Products : enterprise_virtualization_manager- EPSS Score: %0.04
- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6493
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.... Read more
Affected Products : icedtea-web- EPSS Score: %0.06
- Published: Mar. 03, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6494
fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows local users to cause a denial of service (prevention of system updates).... Read more
- EPSS Score: %0.06
- Published: Dec. 02, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0056
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.... Read more
- EPSS Score: %0.22
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-2286
Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote authenticated users to affect availability, related to ZFS.... Read more
Affected Products : solaris- EPSS Score: %0.36
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-2714
Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonst... Read more
- EPSS Score: %0.10
- Published: May. 14, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1108
The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.... Read more
Affected Products : iphone_os- EPSS Score: %0.07
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-3448
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.... Read more
Affected Products : rest-client- EPSS Score: %0.06
- Published: Apr. 29, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-5560
The default configuration in mate-settings-daemon 1.5.3 allows local users to change the timezone for the system via a crafted D-Bus call.... Read more
Affected Products : mate-settings-daemon- EPSS Score: %0.06
- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-6109
The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows... Read more
- EPSS Score: %2.88
- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-3079
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to bypass authorization checks and visit unspecified URLs with license-usage data via a DESCRIBE clause in a SPARQL qu... Read more
Affected Products : rational_license_key_server- EPSS Score: %0.37
- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025