Latest CVE Feed
-
2.1
LOWCVE-2013-0980
The Passcode Lock implementation in Apple iOS before 6.1.3 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging an error in the emergency-call feature.... Read more
Affected Products : iphone_os- EPSS Score: %0.05
- Published: Mar. 20, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-2489
Unspecified vulnerability in the utdmsession program in Sun Ray Server Software (SRSS) 4.0 allows local users to access the sessions of arbitrary users via unknown vectors.... Read more
Affected Products : ray_server_software- EPSS Score: %0.06
- Published: Jul. 16, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-3430
The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg sy... Read more
Affected Products : linux_kernel- EPSS Score: %0.20
- Published: Oct. 03, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-0369
MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that... Read more
Affected Products : mysql- EPSS Score: %0.12
- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1857
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.... Read more
Affected Products : web_jetadmin- EPSS Score: %78.04
- Published: Mar. 24, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1412
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.... Read more
Affected Products : mac_os_x- EPSS Score: %0.23
- Published: Nov. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-2658
Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the DRIVER option. NOTE: this issue might not be a vulnerability, since the ability to set this option typicall... Read more
Affected Products : unixodbc- EPSS Score: %0.08
- Published: Aug. 31, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-4446
Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a change made by an admin... Read more
Affected Products : os_x_server- EPSS Score: %0.12
- Published: Oct. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-1999-1221
dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.... Read more
Affected Products : unix- EPSS Score: %0.07
- Published: Nov. 17, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-1877
tss 0.8.1 allows local users to read arbitrary files via the -a parameter, which is processed while tss is running with privileges.... Read more
Affected Products : tss- EPSS Score: %0.06
- Published: Apr. 17, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2001-1551
Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs.... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-1366
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.... Read more
- EPSS Score: %0.09
- Published: May. 02, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-1205
nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.... Read more
Affected Products : hp-ux- EPSS Score: %0.18
- Published: Jun. 07, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0132
Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.... Read more
- EPSS Score: %0.36
- Published: Aug. 15, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0464
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.... Read more
Affected Products : tripwire- EPSS Score: %0.08
- Published: Jan. 04, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1977
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.... Read more
Affected Products : devstack- EPSS Score: %0.11
- Published: May. 21, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-0040
Vulnerability in SGI IRIX 6.5.11 through 6.5.15f allows local users to cause privileged applications to dump core via the HOSTALIASES environment variable, which might allow the users to gain privileges.... Read more
Affected Products : irix- EPSS Score: %0.06
- Published: Mar. 28, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1394
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a d... Read more
Affected Products : bsd- EPSS Score: %0.90
- Published: Jul. 02, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1423
ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.... Read more
- EPSS Score: %0.33
- Published: Jun. 26, 1997
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1786
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Company theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.23
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025