Latest CVE Feed
-
1.9
LOWCVE-2014-5030
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.... Read more
- EPSS Score: %0.05
- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-4037
The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.... Read more
Affected Products : qemu- EPSS Score: %0.10
- Published: Aug. 26, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-0245
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race... Read more
- EPSS Score: %0.04
- Published: Feb. 13, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2012-3432
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial o... Read more
Affected Products : xen- EPSS Score: %1.42
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-2636
net/bridge/br_mdb.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Mar. 22, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-2898
drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted devi... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2009-2490
Unspecified vulnerability in the utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to cause a denial of service (audio outage) or possibly gain privileges via unknown vectors related to "... Read more
Affected Products : ray_server_software- EPSS Score: %0.06
- Published: Jul. 16, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2013-5187
The Screen Lock implementation in Apple Mac OS X before 10.9 does not immediately accept Keychain Status menu Lock Screen commands, and instead incorrectly relies on a certain timeout setting, which allows physically proximate attackers to obtain sensitiv... Read more
- EPSS Score: %0.13
- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2008-0049
AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applicat... Read more
- EPSS Score: %0.19
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-2470
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files ... Read more
Affected Products : bugzilla- EPSS Score: %0.04
- Published: Jun. 28, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-1352
Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors.... Read more
Affected Products : iphone_os- EPSS Score: %0.07
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2009-1296
The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk. NOTE: the log files are on... Read more
- EPSS Score: %0.07
- Published: Jun. 09, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2013-7336
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirt... Read more
- EPSS Score: %0.07
- Published: May. 07, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2008-3230
The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif.... Read more
Affected Products : lavf_demuxer- EPSS Score: %0.12
- Published: Jul. 18, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2014-0058
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %0.06
- Published: Feb. 26, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-7404
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka Spectrum Protect for Databases) 5.5 before 5.5.6.2, 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; Tivoli Storage Manager for Mail: Data Protection for ... Read more
- EPSS Score: %0.03
- Published: Nov. 14, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-6195
The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 before 6.2.5.2 on... Read more
- EPSS Score: %0.04
- Published: Feb. 14, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2010-4073
The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_... Read more
- EPSS Score: %0.24
- Published: Nov. 29, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-3431
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unin... Read more
- EPSS Score: %0.08
- Published: Jan. 24, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-3153
dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink attack on ~/.dmrc.... Read more
- EPSS Score: %0.05
- Published: Mar. 06, 2014
- Modified: Apr. 12, 2025