Latest CVE Feed
-
2.1
LOWCVE-2011-0995
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.... Read more
- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-1788
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.... Read more
Affected Products : vcenter- Published: May. 09, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-5075
Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINFO_RESULTS DeviceIoControl request to \\.\aswFW.... Read more
Affected Products : avast\!_internet_security- Published: Dec. 28, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2009-0675
The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the dr... Read more
Affected Products : linux_kernel- Published: Feb. 22, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-1375
Intel Graphics Driver in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.... Read more
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0059
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.... Read more
Affected Products : jboss_enterprise_application_platform- Published: Nov. 17, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-0450
Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions for Firefox Recovery Key.html, which might allow local users to read a Firefox Sync key via standard filesystem operations.... Read more
- Published: Feb. 01, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-2209
Integer signedness error in the osf_sysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call.... Read more
Affected Products : linux_kernel- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4138
Cross-site scripting (XSS) vulnerability in the Hatch theme 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with the "Administer content," "Create new article," or "Edit any article type content" permission to inject arbitrary web scri... Read more
- Published: Aug. 28, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-4021
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to impersonate a client by rewriting an inner request, aka a "... Read more
Affected Products : kerberos_5- Published: Dec. 02, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0056
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.... Read more
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-2389
hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials.... Read more
Affected Products : hostapd- Published: Jun. 21, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-1378
IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.... Read more
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-2343
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of service (excessive data processing) via a crafted DNP request over a serial line.... Read more
Affected Products : scada_data_gateway- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4218
The InitMethodAndPassword function in InfraStack/OSAgnostic/WiMax/Agents/Supplicant/Source/SupplicantAgent.c in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses the same RSA private key in supplicant_key.... Read more
Affected Products : wimax_network_service- Published: Aug. 25, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-1279
Apple TV before 6.1 does not properly restrict logging, which allows local users to obtain sensitive information by reading log data.... Read more
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-1834
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.... Read more
Affected Products : http_server- Published: Mar. 20, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-0201
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files.... Read more
Affected Products : rhevm-reports- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-100039
mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these details are obtained from third pa... Read more
Affected Products : malwarebytes_anti-exploit- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4274
Cross-site scripting (XSS) vulnerability in the password_policy_admin_view function in password_policy.admin.inc in the Password Policy module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Adminis... Read more
- Published: Aug. 28, 2013
- Modified: Apr. 11, 2025