Latest CVE Feed
-
1.9
LOWCVE-2012-6539
The dev_ifconf function in net/socket.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-1056
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.... Read more
Affected Products : ubuntu_linux- EPSS Score: %0.05
- Published: Oct. 28, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-6540
The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 3.6 does not initialize a certain structure for IP_VS_SO_GET_TIMEOUT commands, which allows local users to obtain sensitive information from kernel stack memory via... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0541
Buffer overflow in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Windows, when a localOS registry is used in conjunction with WebSphere Identity Manger (WIM), allows local us... Read more
- EPSS Score: %0.05
- Published: Apr. 24, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0527
The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the sc... Read more
Affected Products : sterling_connect_direct_user_interface- EPSS Score: %0.06
- Published: Jun. 21, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-6549
The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-5496
Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composit... Read more
- EPSS Score: %0.07
- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2013-1952
Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service ... Read more
Affected Products : xen- EPSS Score: %0.07
- Published: May. 13, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-1197
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.... Read more
Affected Products : cpio- EPSS Score: %3.33
- Published: Feb. 19, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2009-2012
Unspecified vulnerability in idmap in Sun OpenSolaris snv_88 through snv_110, when a CIFS server is enabled, allows local users to cause a denial of service (idpmapd daemon crash and idmapd outage) via unknown vectors.... Read more
Affected Products : opensolaris- EPSS Score: %0.06
- Published: Jun. 09, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2005-3126
The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on temporary (a) output and (b) error files.... Read more
Affected Products : antiword- EPSS Score: %0.06
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2013-4509
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user passw... Read more
- EPSS Score: %0.08
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2016-0436
Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-... Read more
Affected Products : retail_applications- EPSS Score: %0.28
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2013-0122
The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app.scanner.DeleteFileActivity with zer... Read more
Affected Products : avast\!_mobile_security- EPSS Score: %0.07
- Published: Apr. 22, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2008-2937
Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.... Read more
Affected Products : postfix- EPSS Score: %0.08
- Published: Aug. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-4525
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Jan. 11, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2008-1383
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same... Read more
Affected Products : linux- EPSS Score: %0.03
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2012-4508
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Dec. 21, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-5438
Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 b... Read more
- EPSS Score: %0.10
- Published: Oct. 13, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-4072
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl sys... Read more
- EPSS Score: %0.10
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025