Latest CVE Feed
-
1.9
LOWCVE-2010-4525
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Jan. 11, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-3310
Multiple integer signedness errors in net/rose/af_rose.c in the Linux kernel before 2.6.36-rc5-next-20100923 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a rose_getname function call... Read more
- EPSS Score: %0.12
- Published: Sep. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2008-2937
Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.... Read more
Affected Products : postfix- EPSS Score: %0.08
- Published: Aug. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2012-6544
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI ... Read more
- EPSS Score: %0.08
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4072
The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl sys... Read more
- EPSS Score: %0.10
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-3850
The eHCA driver in Linux kernel 2.6 before 2.6.22, when running on PowerPC, does not properly map userspace resources, which allows local users to read portions of physical address space.... Read more
- EPSS Score: %0.06
- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2008-1383
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same... Read more
Affected Products : linux- EPSS Score: %0.03
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2012-0742
IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.... Read more
Affected Products : tivoli_event_pump- EPSS Score: %0.05
- Published: Apr. 09, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0122
The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app.scanner.DeleteFileActivity with zer... Read more
Affected Products : avast\!_mobile_security- EPSS Score: %0.07
- Published: Apr. 22, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2009-3432
Unspecified vulnerability in xscreensaver in Sun Solaris 10, and OpenSolaris before snv_112, when Xorg or Xnewt is used and RandR is enabled, allows physically proximate attackers to read a locked screen via unknown vectors related to XRandR resize events... Read more
- EPSS Score: %0.07
- Published: Sep. 28, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2015-1114
The Sandbox Profiles component in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to discover hardware identifiers via a crafted app.... Read more
- EPSS Score: %0.07
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-3956
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-de... Read more
- EPSS Score: %0.11
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2013-0349
The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCON... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Feb. 28, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-0218
Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a ... Read more
Affected Products : xen- EPSS Score: %0.07
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-0017
The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtai... Read more
Affected Products : libssh- EPSS Score: %0.08
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-0019
Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.... Read more
- EPSS Score: %0.09
- Published: Feb. 04, 2014
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-3520
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Oct. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2008-0038
Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application.... Read more
Affected Products : mac_os_x- EPSS Score: %0.07
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2012-2737
The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via... Read more
Affected Products : accountsservice- EPSS Score: %0.07
- Published: Jul. 22, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-4944
Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.... Read more
Affected Products : python- EPSS Score: %0.04
- Published: Aug. 27, 2012
- Modified: Apr. 11, 2025