Latest CVE Feed
-
1.9
LOWCVE-2012-6540
The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 3.6 does not initialize a certain structure for IP_VS_SO_GET_TIMEOUT commands, which allows local users to obtain sensitive information from kernel stack memory via... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-1106
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local user... Read more
Affected Products : automatic_bug_reporting_tool- EPSS Score: %0.05
- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-6549
The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0527
The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the sc... Read more
Affected Products : sterling_connect_direct_user_interface- EPSS Score: %0.06
- Published: Jun. 21, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-0473
The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.... Read more
Affected Products : smb4k- EPSS Score: %0.06
- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2012-6538
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADM... Read more
- EPSS Score: %0.06
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-1427
The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as for... Read more
- EPSS Score: %0.06
- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2008-4579
The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.... Read more
- EPSS Score: %0.05
- Published: Oct. 15, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2024-53995
SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the ... Read more
Affected Products :- Published: Jan. 08, 2025
- Modified: Jan. 08, 2025
- Vuln Type: Authentication
-
1.9
LOWCVE-2008-3644
Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.... Read more
Affected Products : safari- EPSS Score: %0.07
- Published: Nov. 17, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2015-6563
The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction... Read more
- EPSS Score: %0.09
- Published: Aug. 24, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-5030
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.... Read more
- EPSS Score: %0.05
- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-2830
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) ... Read more
- EPSS Score: %0.03
- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-0245
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race... Read more
- EPSS Score: %0.04
- Published: Feb. 13, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-4037
The slirp_smb function in net/slirp.c in QEMU 2.3.0 and earlier creates temporary files with predictable names, which allows local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program.... Read more
Affected Products : qemu- EPSS Score: %0.10
- Published: Aug. 26, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-1420
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a fil... Read more
- EPSS Score: %0.04
- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2012-3741
The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via an app that perfo... Read more
Affected Products : iphone_os- EPSS Score: %0.05
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-3734
Office Viewer in Apple iOS before 6 writes cleartext document data to a temporary file, which might allow local users to bypass a document's intended (1) Data Protection level or (2) encryption state by reading the temporary content.... Read more
Affected Products : iphone_os- EPSS Score: %0.04
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4083
The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) IPC_INFO, (2) SEM_INFO, (3) IPC... Read more
- EPSS Score: %0.09
- Published: Nov. 30, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0979
lockdownd in Lockdown in Apple iOS before 6.1.3 does not properly consider file types during the permission-setting step of a backup restoration, which allows local users to change the permissions of arbitrary files via a backup that contains a pathname w... Read more
Affected Products : iphone_os- EPSS Score: %0.04
- Published: Mar. 20, 2013
- Modified: Apr. 11, 2025