Latest CVE Feed
-
1.9
LOWCVE-2015-0430
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality via vectors related to RPC Utility.... Read more
- EPSS Score: %0.08
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2011-1155
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a file... Read more
Affected Products : logrotate- EPSS Score: %0.09
- Published: Mar. 30, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-6542
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverag... Read more
- EPSS Score: %0.09
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2005-3126
The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on temporary (a) output and (b) error files.... Read more
Affected Products : antiword- EPSS Score: %0.06
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2013-4369
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.... Read more
Affected Products : xen- EPSS Score: %0.06
- Published: Oct. 17, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-4535
Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."... Read more
Affected Products : xen- EPSS Score: %0.11
- Published: Nov. 21, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0527
The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the sc... Read more
Affected Products : sterling_connect_direct_user_interface- EPSS Score: %0.06
- Published: Jun. 21, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2009-2911
SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel... Read more
Affected Products : systemtap- EPSS Score: %0.08
- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2011-1016
The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve registers, which allows local users to write to arbitrary memory locations associated with (1) Video RAM (aka VRAM) or (2) the Graphics Tr... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Feb. 28, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-2204
Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive informat... Read more
Affected Products : tomcat- EPSS Score: %0.07
- Published: Jun. 29, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-5496
Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composit... Read more
- EPSS Score: %0.07
- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2007-0473
The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.... Read more
Affected Products : smb4k- EPSS Score: %0.06
- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2011-1310
The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which... Read more
Affected Products : websphere_application_server- EPSS Score: %0.05
- Published: Mar. 08, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-0413
Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability.... Read more
- EPSS Score: %0.10
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-0010
The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows... Read more
- EPSS Score: %1.31
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-2662
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect availability via vectors related to DHCP Server.... Read more
Affected Products : solaris- EPSS Score: %0.22
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2012-6548
The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.... Read more
- EPSS Score: %0.02
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-1096
IOHIDFamily in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app.... Read more
- EPSS Score: %0.07
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2012-6541
The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2016-0453
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.1.2 allows remote attackers to affect integrity via unknown vectors related to Embedded Server.... Read more
- EPSS Score: %0.52
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025