Latest CVE Feed
-
2.1
LOWCVE-2014-4446
Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a change made by an admin... Read more
Affected Products : os_x_server- Published: Oct. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-7080
Siri in Apple iOS before 9.2 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.... Read more
Affected Products : iphone_os- Published: Dec. 11, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5449
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.... Read more
- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-1983
The arch_get_unmapped_area function in mmap.c in the PaX patches for Linux kernel 2.6, when Address Space Layout Randomization (ASLR) is enabled, allows local users to cause a denial of service (infinite loop) via unknown attack vectors.... Read more
- Published: May. 02, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3813
A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.... Read more
Affected Products : enterprise_linux- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-5447
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0... Read more
- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-8834
UserAccountUpdater in Apple OS X 10.10 before 10.10.2 stores a PDF document's password in a printing preference file, which allows local users to obtain sensitive information by reading a file.... Read more
- Published: Jan. 30, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-0394
A "potential" buffer overflow exists in the panic() function in Linux 2.4.x, although it may not be exploitable due to the functionality of panic.... Read more
Affected Products : linux_kernel- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-5240
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted... Read more
- Published: Aug. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-4529
Integer underflow in the irda_getsockopt function in net/irda/af_irda.c in the Linux kernel before 2.6.37 on platforms other than x86 allows local users to obtain potentially sensitive information from kernel heap memory via an IRLMP_ENUMDEVICES getsockop... Read more
Affected Products : linux_kernel- Published: Jan. 13, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-7835
webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site... Read more
Affected Products : moodle- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5247
The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API ... Read more
- Published: Aug. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5398
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XM... Read more
Affected Products : wonderware_information_server- Published: Aug. 28, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2002-1319
The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.... Read more
- Published: Dec. 11, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-4341
The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.... Read more
- Published: Jan. 25, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-8526
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information by reading a Java stack trace.... Read more
Affected Products : network_data_loss_prevention- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5270
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the abil... Read more
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9418
The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users to cause a denial of service (memory overflow) via unspecified vectors.... Read more
Affected Products : espace_desktop- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9417
The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted image.... Read more
Affected Products : espace_desktop- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-4175
Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.... Read more
Affected Products : insyde_bios- Published: Dec. 11, 2005
- Modified: Apr. 03, 2025