Latest CVE Feed
-
1.9
LOWCVE-2008-2937
Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.... Read more
Affected Products : postfix- EPSS Score: %0.08
- Published: Aug. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-4525
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Jan. 11, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-0179
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU... Read more
- EPSS Score: %0.11
- Published: Aug. 03, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2011-4029
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a ... Read more
Affected Products : x_server- EPSS Score: %0.57
- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-3850
The eHCA driver in Linux kernel 2.6 before 2.6.22, when running on PowerPC, does not properly map userspace resources, which allows local users to read portions of physical address space.... Read more
- EPSS Score: %0.06
- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2013-2976
The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 does not properly perform caching, which allows local users to obtain sensitive information via unspe... Read more
Affected Products : websphere_application_server- EPSS Score: %0.05
- Published: Aug. 21, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-0822
umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, whi... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2007-5438
Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 b... Read more
- EPSS Score: %0.10
- Published: Oct. 13, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2008-1383
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same... Read more
Affected Products : linux- EPSS Score: %0.03
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-4072
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl sys... Read more
- EPSS Score: %0.10
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-6146
IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.06
- Published: Nov. 08, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2013-2168
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.... Read more
- EPSS Score: %0.09
- Published: Jul. 03, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2005-3349
GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.... Read more
Affected Products : gnump3d- EPSS Score: %0.04
- Published: Nov. 18, 2005
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2014-0076
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.... Read more
Affected Products : openssl- EPSS Score: %0.67
- Published: Mar. 25, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2008-0038
Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application.... Read more
Affected Products : mac_os_x- EPSS Score: %0.07
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2011-4944
Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.... Read more
Affected Products : python- EPSS Score: %0.04
- Published: Aug. 27, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-2635
The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Mar. 22, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-0135
Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.... Read more
Affected Products : kafo- EPSS Score: %0.04
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2012-6547
The __tun_chr_ioctl function in drivers/net/tun.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.02
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-1114
The Sandbox Profiles component in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to discover hardware identifiers via a crafted app.... Read more
- EPSS Score: %0.07
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025