Latest CVE Feed
-
2.1
LOWCVE-2013-3042
Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.... Read more
- Published: Dec. 14, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-3043
Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.... Read more
- Published: Dec. 14, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-6493
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.... Read more
Affected Products : icedtea-web- Published: Mar. 03, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6402
base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file.... Read more
Affected Products : linux_imaging_and_printing_project- Published: Jan. 05, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4498
The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authentica... Read more
- Published: May. 17, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-2190
The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.... Read more
Affected Products : cherokee- Published: Oct. 07, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0222
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the uniq command, which triggers a stack-based buffer overflow in the alloca function.... Read more
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4354
The API before 2.1 in OpenStack Image Registry and Delivery Service (Glance) makes it easier for local users to inject images into arbitrary tenants by adding the tenant as a member of the image.... Read more
Affected Products : image_registry_and_delivery_service_\(glance\)- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-5380
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : maximo_asset_management- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4361
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.... Read more
Affected Products : xen- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4503
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options.... Read more
Affected Products : feed_element_mapper- Published: May. 13, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-4701
WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file.... Read more
- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-4455
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.... Read more
Affected Products : katello_installer- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4427
pyxtrlock before 0.2 does not properly check the return values of the (1) xcb_grab_pointer and (2) xcb_grab_keyboard XCB library functions, which allows physically proximate attackers to gain access to the keyboard or mouse without unlocking the screen vi... Read more
Affected Products : pyxtrlock- Published: May. 19, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-2978
Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CV... Read more
Affected Products : cognos_business_intelligence- Published: Aug. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-3564
Unspecified vulnerability in Oracle GlassFish Enterprise Server 2.1.1 allows local users to affect confidentiality via unknown vectors related to Administration.... Read more
Affected Products : sun_glassfish_enterprise_server- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-6372
The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.... Read more
Affected Products : subversion-plugin- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6497
clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file.... Read more
Affected Products : clamav- Published: Dec. 01, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-2539
Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files.... Read more
- Published: Aug. 02, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-4922
cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.... Read more
Affected Products : pidgin- Published: Aug. 08, 2012
- Modified: Apr. 11, 2025