Latest CVE Feed
-
2.1
LOWCVE-2015-5851
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.... Read more
- EPSS Score: %0.06
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-7230
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.... Read more
- EPSS Score: %0.12
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-3615
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.... Read more
- EPSS Score: %0.09
- Published: Nov. 01, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-5619
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activit... Read more
Affected Products : the_sleuth_kit- EPSS Score: %0.10
- Published: Sep. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-3107
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than... Read more
Affected Products : fusion_middleware- EPSS Score: %0.62
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2025-30371
Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link access protection in GeoJson endpoint. Self hosted Metabase instances that are us... Read more
Affected Products : metabase- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Misconfiguration
-
2.1
LOWCVE-2025-21085
PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.... Read more
Affected Products : pingfederate- Published: Jun. 15, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Denial of Service
-
2.1
LOWCVE-2013-4229
Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users with permissions to add pages to inject arbitrary web script or HTML via a title in the page settings.... Read more
- EPSS Score: %0.25
- Published: Aug. 21, 2013
- Modified: Aug. 27, 2025
-
2.1
LOWCVE-2024-9101
A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is un... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
2.1
LOWCVE-2004-2436
Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges.... Read more
- EPSS Score: %0.08
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1056
The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one... Read more
- EPSS Score: %0.08
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-4080
Multiple unspecified vulnerabilities in ldap_cachemgr (aka the LDAP client configuration cache daemon) in Sun Solaris 9 and 10, and OpenSolaris before snv_78, allow local users to cause a denial of service (daemon crash) via vectors involving multiple ser... Read more
- EPSS Score: %0.06
- Published: Nov. 29, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-6551
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows local users to affect confidentiality via vectors related to CLIENT:MYSQLADMIN.... Read more
- EPSS Score: %0.16
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-3720
The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that re... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-3277
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web... Read more
- EPSS Score: %0.10
- Published: Sep. 28, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-6680
Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy.... Read more
Affected Products : aix- EPSS Score: %0.07
- Published: Jan. 10, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-5456
Cross-site scripting (XSS) vulnerability in the Social Stats module before 7.x-1.5 for Drupal allows remote authenticated users with the "[Content Type]: Create new content" permission to inject arbitrary web script or HTML via vectors related to the conf... Read more
Affected Products : social_stats- EPSS Score: %0.20
- Published: Aug. 25, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2008-3898
Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations ... Read more
Affected Products : drivecrypt_plus_pack- EPSS Score: %0.06
- Published: Sep. 03, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-3380
Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.... Read more
- EPSS Score: %0.17
- Published: Aug. 31, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-0384
Tor 0.2.2.x before 0.2.2.7-alpha, when functioning as a directory mirror, does not prevent logging of the client IP address upon detection of erroneous client behavior, which might make it easier for local users to discover the identities of clients in op... Read more
- EPSS Score: %0.06
- Published: Jan. 25, 2010
- Modified: Apr. 11, 2025