Latest CVE Feed
-
2.1
LOWCVE-2011-1172
net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially se... Read more
Affected Products : linux_kernel- Published: Jun. 22, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-1764
Linux 2.6.11 on 64-bit x86 (x86_64) platforms does not use a guard page for the 47-bit address page to protect against an AMD K8 bug, which allows local users to cause a denial of service.... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1841
The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.... Read more
Affected Products : acrobat_reader- Published: Jul. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2104
sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.... Read more
Affected Products : sysreport- Published: Oct. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-3834
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.... Read more
- Published: Oct. 07, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-2110
Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root.... Read more
Affected Products : vserver- Published: May. 01, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6206
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow... Read more
- Published: Dec. 04, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-0368
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer ... Read more
Affected Products : opensc- Published: Mar. 02, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-0056
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.... Read more
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-4021
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, aka a "... Read more
Affected Products : kerberos_5- Published: Dec. 02, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-7127
Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local users to obtain sensitive information by reading this file.... Read more
- Published: Dec. 17, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0711
The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V... Read more
- Published: Mar. 01, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0181
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations... Read more
- Published: Apr. 27, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0202
The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database password in cleartext, which allows local users to obtain sensitive information by ... Read more
Affected Products : rhevm-dwh- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0201
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files.... Read more
Affected Products : rhevm-reports- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6956
Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4 before 7.4r6, and 8.0 before 8.0r1, when web rewrite is... Read more
Affected Products : ive_os- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-6216
Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors.... Read more
- Published: Apr. 12, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-0450
Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions for Firefox Recovery Key.html, which might allow local users to read a Firefox Sync key via standard filesystem operations.... Read more
- Published: Feb. 01, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0189
virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file.... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation virt-who- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0059
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.... Read more
Affected Products : jboss_enterprise_application_platform- Published: Nov. 17, 2014
- Modified: Apr. 12, 2025