Latest CVE Feed
-
1.9
LOWCVE-2011-1019
The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 01, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-1114
The Sandbox Profiles component in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to discover hardware identifiers via a crafted app.... Read more
- EPSS Score: %0.07
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-3956
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-de... Read more
- EPSS Score: %0.11
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2012-6545
The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.... Read more
- EPSS Score: %0.08
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0200
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hp... Read more
- EPSS Score: %0.06
- Published: Mar. 06, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2009-1215
Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.... Read more
- EPSS Score: %0.09
- Published: Apr. 01, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2008-6722
Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attackers to obtain a logged-in session by using a victim's web-browser process that continues to send the original and valid SSL sessionID,... Read more
Affected Products : access_manager- EPSS Score: %0.06
- Published: Apr. 14, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2013-4025
IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it... Read more
- EPSS Score: %0.08
- Published: Sep. 25, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4212
The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data.... Read more
- EPSS Score: %0.07
- Published: Nov. 09, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-3541
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows local users to affect availability via unknown vectors related to Outside In Filters.... Read more
Affected Products : fusion_middleware- EPSS Score: %0.47
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-0890
The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is used, logs cleartext passwords during Audio/Video chat sessions, which allows local us... Read more
- EPSS Score: %0.05
- Published: Mar. 06, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2010-2387
vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the informat... Read more
Affected Products : gnome_display_manager- EPSS Score: %0.09
- Published: Dec. 21, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-2873
SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by ... Read more
Affected Products : spamassassin- EPSS Score: %0.06
- Published: Jun. 11, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2007-4308
The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.... Read more
- EPSS Score: %0.06
- Published: Aug. 13, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2012-3729
The Berkeley Packet Filter (BPF) interpreter implementation in the kernel in Apple iOS before 6 accesses uninitialized memory locations, which allows local users to obtain sensitive information about the layout of kernel memory via a crafted program that ... Read more
Affected Products : iphone_os- EPSS Score: %0.07
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-4481
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."... Read more
- EPSS Score: %0.03
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-2580
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect availability via vectors related to NFSv4.... Read more
Affected Products : solaris- EPSS Score: %0.22
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2010-1650
IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects,... Read more
Affected Products : websphere_application_server- EPSS Score: %0.07
- Published: May. 03, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-2470
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files ... Read more
Affected Products : bugzilla- EPSS Score: %0.04
- Published: Jun. 28, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-4448
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.... Read more
Affected Products : iphone_os- EPSS Score: %0.05
- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025