Latest CVE Feed
-
2.1
LOWCVE-2005-2104
sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.... Read more
Affected Products : sysreport- Published: Oct. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-6387
Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.... Read more
Affected Products : drupal- Published: Dec. 24, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0103
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.... Read more
- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-2462
Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and possibly remote attackers to gain privileges.... Read more
Affected Products : liveresponse- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2011-1172
net/ipv6/netfilter/ip6_tables.c in the IPv6 implementation in the Linux kernel before 2.6.39 does not place the expected '\0' character at the end of string data in the values of certain structure members, which allows local users to obtain potentially se... Read more
Affected Products : linux_kernel- Published: Jun. 22, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-2607
A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users to read portions of kernel memory via a large len argument, which is received as an int but cast to a short, which prevents a read loo... Read more
Affected Products : linux_kernel- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1764
Linux 2.6.11 on 64-bit x86 (x86_64) platforms does not use a guard page for the 47-bit address page to protect against an AMD K8 bug, which allows local users to cause a denial of service.... Read more
Affected Products : linux_kernel- Published: Oct. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0535
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sour... Read more
Affected Products : linux_kernel suse_linux linux linux mandrake_linux mandrake_linux_corporate_server mandrake_multi_network_firewall secure_linux secure_community suse_email_server +7 more products- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-1636
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to re... Read more
Affected Products : linux_kernel- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2024-38638
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify or corrupt memory. QTS 5.2.x/QuTS hero h5... Read more
- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Memory Corruption
-
2.1
LOWCVE-2015-7971
Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALL_xenoprof_op hypercalls, which ar... Read more
Affected Products : xen- Published: Oct. 30, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-8100
The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.... Read more
Affected Products : net-snmp- Published: Nov. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-7972
The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allow... Read more
Affected Products : xen- Published: Oct. 30, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-8025
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.... Read more
- Published: Nov. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-1999-1205
nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.... Read more
Affected Products : hp-ux- Published: Jun. 07, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0132
Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.... Read more
- Published: Aug. 15, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-1877
tss 0.8.1 allows local users to read arbitrary files via the -a parameter, which is processed while tss is running with privileges.... Read more
Affected Products : tss- Published: Apr. 17, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-1786
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Company theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-1977
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.... Read more
Affected Products : devstack- Published: May. 21, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-2070
Cross-site scripting (XSS) vulnerability in the MultiBlock module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer blocks permission to inject arbitrary web script or HTML via the block tit... Read more
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025