Latest CVE Feed
-
2.1
LOWCVE-2013-6216
Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors.... Read more
- Published: Apr. 12, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2009-0368
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer ... Read more
Affected Products : opensc- Published: Mar. 02, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-5158
The Social subsystem in Apple iOS before 7 does not properly restrict access to the cache of Twitter icons, which allows physically proximate attackers to obtain sensitive information about recent Twitter interaction via unspecified vectors.... Read more
Affected Products : iphone_os- Published: Sep. 19, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-6372
The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.... Read more
Affected Products : subversion-plugin- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-1831
Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.... Read more
Affected Products : passenger- Published: Feb. 19, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-2190
The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.... Read more
Affected Products : cherokee- Published: Oct. 07, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-5872
Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to Name Service Cache Daemon (NSCD).... Read more
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0056
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.... Read more
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9584
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memo... Read more
- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-1771
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than... Read more
Affected Products : fusion_middleware- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-0791
The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application failure) via unspecified vectors that trigger the creation of a /etc/mtab~ file... Read more
Affected Products : ncpfs- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-0118
helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.... Read more
Affected Products : helvis- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0372
xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.... Read more
Affected Products : xine- Published: Apr. 15, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-3100
usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which allows local users to cause a denial of service (hang)... Read more
- Published: Jun. 14, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-0233
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-3099
usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of se... Read more
Affected Products : enterprise_linux- Published: Jun. 14, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-1395
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwagent, and (2) overwrite and create arbitrary files via imm... Read more
Affected Products : internet_message- Published: Jan. 17, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-5488
Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via un... Read more
Affected Products : mailchimp- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5697
The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6 does not initialize a certain bitmap data structure, which allows local users to obtain sensitive information from kernel memory via a GET_BITMAP_FILE ioctl call.... Read more
Affected Products : linux_kernel- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5495
Cross-site scripting (XSS) vulnerability in the Mobile sliding menu module 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer menu" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mobile_sliding_menu- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025