Latest CVE Feed
-
1.9
LOWCVE-2007-0822
umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, whi... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2014-4421
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different ... Read more
- EPSS Score: %0.08
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2010-4072
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl sys... Read more
- EPSS Score: %0.10
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-4508
Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Dec. 21, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-4029
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a ... Read more
Affected Products : x_server- EPSS Score: %0.57
- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-0179
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU... Read more
- EPSS Score: %0.11
- Published: Aug. 03, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2011-4098
The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jun. 08, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2008-6561
Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.... Read more
- EPSS Score: %0.08
- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-4758
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password... Read more
Affected Products : otrs- EPSS Score: %0.06
- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-5118
Multiple race conditions in Comodo Internet Security before 5.8.213334.2131 allow local users to bypass the Defense+ feature via unspecified vectors.... Read more
Affected Products : comodo_internet_security- EPSS Score: %0.04
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2015-1798
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MA... Read more
Affected Products : ntp- EPSS Score: %0.68
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2013-7291
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree,"... Read more
Affected Products : memcached- EPSS Score: %0.21
- Published: Jan. 13, 2014
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2012-2425
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allow remote attackers to cause a denial of service (application crash) v... Read more
- EPSS Score: %0.21
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2016-8284
Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows local users to affect availability via vectors related to Server: Replication.... Read more
Affected Products : mysql- EPSS Score: %0.08
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2024-2567
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in jurecapuder AndroidWeatherApp 1.0.0 on Android. Affected is an unknown function of the file androidmanifest.xml of the component Backup File Handler. The ma... Read more
Affected Products :- Published: Mar. 17, 2024
- Modified: Nov. 21, 2024
-
1.8
LOWCVE-2014-4812
The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to this port.... Read more
Affected Products : security_appscan_source- EPSS Score: %0.11
- Published: Oct. 26, 2014
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2021-2147
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Installation). The supported version that is affected is 8.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure w... Read more
- EPSS Score: %0.08
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
1.8
LOWCVE-2025-0885
Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow unauthorized access to calendar items marked private. This issue affects GroupWise versio... Read more
Affected Products :- Published: Jul. 03, 2025
- Modified: Jul. 03, 2025
-
1.8
LOWCVE-2007-2999
Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers t... Read more
- EPSS Score: %1.25
- Published: Jun. 04, 2007
- Modified: Apr. 09, 2025
-
1.8
LOWCVE-2025-23206
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprin... Read more
Affected Products : aws_cloud_development_kit- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025