Latest CVE Feed
-
1.9
LOWCVE-2014-5232
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the app in the background state.... Read more
- EPSS Score: %0.05
- Published: Jan. 14, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2008-3876
Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a ... Read more
Affected Products : iphone- EPSS Score: %0.06
- Published: Sep. 02, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2014-9415
Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QES file.... Read more
Affected Products : espace_desktop- EPSS Score: %0.11
- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2009-5084
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a password, which might allow local users to obtain sensitive inf... Read more
Affected Products : tivoli_federated_identity_manager- EPSS Score: %0.05
- Published: Aug. 12, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2003-1588
Sun Cluster 2.2, when HA-Oracle or HA-Sybase DBMS services are used, stores database credentials in cleartext in a cluster configuration file, which allows local users to obtain sensitive information by reading this file.... Read more
Affected Products : cluster- EPSS Score: %0.06
- Published: Feb. 08, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-2619
Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags."... Read more
Affected Products : xenserver- EPSS Score: %0.09
- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-5119
Multiple race conditions in Comodo Internet Security before 5.8.211697.2124 allow local users to bypass the Defense+ feature via unspecified vectors.... Read more
Affected Products : comodo_internet_security- EPSS Score: %0.04
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-6384
(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB passwo... Read more
Affected Products : ceilometer- EPSS Score: %0.06
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-2693
The perf subsystem in the kernel package 2.6.32-122.el6.x86_64 in Red Hat Enterprise Linux (RHEL) 6 does not properly handle NMIs, which might allow local users to cause a denial of service (excessive log messages) via unspecified vectors.... Read more
Affected Products : enterprise_linux- EPSS Score: %0.05
- Published: Jun. 08, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-1901
The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands.... Read more
Affected Products : infosphere_information_server- EPSS Score: %0.06
- Published: Jun. 28, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2011-3693
NetSaro Enterprise Messenger Server 2.0 allows local users to discover cleartext server credentials by reading the NetSaro.fdb file.... Read more
Affected Products : enterprise_messenger_server- EPSS Score: %0.06
- Published: Sep. 27, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2003-1399
eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.... Read more
Affected Products : eject- EPSS Score: %0.06
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2010-5292
Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.... Read more
Affected Products : amberdms_billing_system- EPSS Score: %0.06
- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-2580
Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script.... Read more
Affected Products : safari- EPSS Score: %0.26
- Published: May. 09, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2014-5036
The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.... Read more
Affected Products : eucalyptus- EPSS Score: %0.06
- Published: Sep. 05, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2010-2371
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1.1 allows local users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-2372.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.07
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2024-53995
SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the ... Read more
Affected Products :- Published: Jan. 08, 2025
- Modified: Jan. 08, 2025
- Vuln Type: Authentication
-
1.9
LOWCVE-2011-1019
The dev_load function in net/core/dev.c in the Linux kernel before 2.6.38 allows local users to bypass an intended CAP_SYS_MODULE capability requirement and load arbitrary modules by leveraging the CAP_NET_ADMIN capability.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 01, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2009-0434
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain ... Read more
Affected Products : websphere_application_server- EPSS Score: %0.06
- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2011-0006
The ima_lsm_rule_init function in security/integrity/ima/ima_policy.c in the Linux kernel before 2.6.37, when the Linux Security Modules (LSM) framework is disabled, allows local users to bypass Integrity Measurement Architecture (IMA) rules in opportunis... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Jun. 21, 2012
- Modified: Apr. 11, 2025