Latest CVE Feed
-
1.9
LOWCVE-2011-1378
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.... Read more
- EPSS Score: %0.06
- Published: Nov. 26, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-3310
Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function call... Read more
- EPSS Score: %0.12
- Published: Sep. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-4421
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different ... Read more
- EPSS Score: %0.08
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-0179
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU... Read more
- EPSS Score: %0.11
- Published: Aug. 03, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2010-4525
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Jan. 11, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4072
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl sys... Read more
- EPSS Score: %0.10
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-4029
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a ... Read more
Affected Products : x_server- EPSS Score: %0.57
- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-0822
umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, whi... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2011-3685
Tembria Server Monitor before 6.0.5 Build 2252 uses a substitution cipher to encrypt application credentials, which allows local users to obtain sensitive information by leveraging read access to (1) authentication.dat or (2) XML files in the Exports dire... Read more
Affected Products : server_monitor- EPSS Score: %0.05
- Published: Sep. 27, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-5423
CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 allows local users to obtain potentially sensitive information by reading a temporary (1) debugging file or (2) developer file.... Read more
Affected Products : pyxis_supplystation- EPSS Score: %0.06
- Published: Oct. 19, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2013-3287
EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console.... Read more
- EPSS Score: %0.06
- Published: Nov. 02, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-4025
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it... Read more
- EPSS Score: %0.08
- Published: Sep. 25, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-6195
The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 before 6.2.5.2 on... Read more
- EPSS Score: %0.04
- Published: Feb. 14, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2017-10120
Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 12.1.0.2. Difficult to exploit vulnerability allows high privileged attacker having Create Session, Select Any Dictionary privilege with log... Read more
- EPSS Score: %0.08
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
1.9
LOWCVE-2016-0436
Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-... Read more
Affected Products : retail_applications- EPSS Score: %0.28
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2024-53855
Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management (ITSM) modules. A user who is authenticated and has view permissions for a ticket, can ... Read more
Affected Products : centurion_erp- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
1.9
LOWCVE-2008-0049
AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applicat... Read more
- EPSS Score: %0.19
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2008-3230
The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif.... Read more
Affected Products : lavf_demuxer- EPSS Score: %0.12
- Published: Jul. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-2470
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files ... Read more
Affected Products : bugzilla- EPSS Score: %0.04
- Published: Jun. 28, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-1650
IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects,... Read more
Affected Products : websphere_application_server- EPSS Score: %0.07
- Published: May. 03, 2010
- Modified: Apr. 11, 2025