Latest CVE Feed
-
1.9
LOWCVE-2012-6543
The l2tp_ip6_getname function in net/l2tp/l2tp_ip6.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-8923
The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store t... Read more
- EPSS Score: %0.12
- Published: Mar. 25, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2008-4230
The Passcode Lock feature in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 displays SMS messages when the emergency-call screen is visible, which allows physically proximate attackers to obtain sensitive information by readi... Read more
- EPSS Score: %0.07
- Published: Nov. 25, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2011-1073
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of files v... Read more
- EPSS Score: %0.02
- Published: Mar. 04, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2009-0437
The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file.... Read more
- EPSS Score: %0.06
- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-1775
Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vectors involving th... Read more
- EPSS Score: %0.05
- Published: Jun. 22, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-1865
The ipv6_getsockopt_sticky function in the kernel in Red Hat Enterprise Linux (RHEL) Beta 5.1.0 allows local users to obtain sensitive information (kernel memory contents) via a negative value of the len parameter. NOTE: this issue has been disputed in a... Read more
Affected Products : enterprise_linux- EPSS Score: %0.05
- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2006-7162
PuTTY 0.59 and earlier uses weak file permissions for (1) ppk files containing private keys generated by puttygen and (2) session logs created by putty, which allows local users to gain sensitive information by reading these files.... Read more
- EPSS Score: %0.04
- Published: Mar. 07, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2015-4808
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via vectors related to Outside In Filters, a different vulnerability than CVE-2015-6013, ... Read more
Affected Products : fusion_middleware- EPSS Score: %0.12
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-5036
The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.... Read more
Affected Products : eucalyptus- EPSS Score: %0.06
- Published: Sep. 05, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2010-2371
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1.1 allows local users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-2372.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.07
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-0700
The client in InfoSphere FastTrack 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly store credentials, which allows local users to bypass intended access restrictions via unspecified vectors.... Read more
- EPSS Score: %0.05
- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-1901
The installer in IBM InfoSphere Information Server 8.5 through 11.3 before 11.3.1.2 allows local users to obtain sensitive information via unspecified commands.... Read more
Affected Products : infosphere_information_server- EPSS Score: %0.06
- Published: Jun. 28, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2012-3116
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows local users to affect confidentiality via unknown vectors.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.09
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2006-1810
Multiple cross-site scripting (XSS) vulnerabilities in FlexBB 0.5.5 BETA allow remote attackers to inject arbitrary web script or HTML via the (1) ICQ, (2) AIM, (3) MSN, (4) Google Talk, (5) Website Name, (6) Website Address, (7) Email Address, (8) Locati... Read more
Affected Products : flexbb- EPSS Score: %0.20
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2014-6540
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.34, before 4.2.26, and before 4.3.14 allows local users to affect availability via vectors related to Graphics driver (WDDM) for Windows guests.... Read more
Affected Products : vm_virtualbox- EPSS Score: %0.17
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2010-4078
The sisfb_ioctl function in drivers/video/sis/sis_main.c in the Linux kernel before 2.6.36-rc6 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FB... Read more
- EPSS Score: %0.07
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4074
The USB subsystem in the Linux kernel before 2.6.36-rc5 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to TIOCGICOUNT ioctl calls, a... Read more
- EPSS Score: %0.08
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4075
The uart_get_count function in drivers/serial/serial_core.c in the Linux kernel before 2.6.37-rc1 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a ... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4077
The ntty_ioctl_tiocgicount function in drivers/char/nozomi.c in the Linux kernel 2.6.36.1 and earlier does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory vi... Read more
Affected Products : linux_kernel- EPSS Score: %0.48
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025