Latest CVE Feed
-
1.9
LOWCVE-2014-0019
Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.... Read more
- EPSS Score: %0.09
- Published: Feb. 04, 2014
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-3741
The Restrictions (aka Parental Controls) implementation in Apple iOS before 6 does not properly handle purchase attempts after a Disable Restrictions action, which allows local users to bypass an intended Apple ID authentication step via an app that perfo... Read more
Affected Products : iphone_os- EPSS Score: %0.05
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0979
lockdownd in Lockdown in Apple iOS before 6.1.3 does not properly consider file types during the permission-setting step of a backup restoration, which allows local users to change the permissions of arbitrary files via a backup that contains a pathname w... Read more
Affected Products : iphone_os- EPSS Score: %0.04
- Published: Mar. 20, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-0218
Xen 3.4, 4.0, and 4.1, when the guest OS has not registered a handler for a syscall or sysenter instruction, does not properly clear a flag for exception injection when injecting a General Protection Fault, which allows local PV guest OS users to cause a ... Read more
Affected Products : xen- EPSS Score: %0.07
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2016-0437
Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0434, CVE-... Read more
Affected Products : retail_applications- EPSS Score: %0.28
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2016-0434
Unspecified vulnerability in the Oracle Retail Point-of-Service component in Oracle Retail Applications 13.4, 14.0, and 14.1 allows local users to affect confidentiality via vectors related to Mobile POS, a different vulnerability than CVE-2016-0436, CVE-... Read more
Affected Products : retail_applications- EPSS Score: %0.28
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2023-20512
A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Oct. 30, 2024
-
1.9
LOWCVE-2012-6140
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem op... Read more
Affected Products : authenticator- EPSS Score: %0.03
- Published: Apr. 24, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2011-3685
Tembria Server Monitor before 6.0.5 Build 2252 uses a substitution cipher to encrypt application credentials, which allows local users to obtain sensitive information by leveraging read access to (1) authentication.dat or (2) XML files in the Exports dire... Read more
Affected Products : server_monitor- EPSS Score: %0.05
- Published: Sep. 27, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-6146
IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows local users to obtain sensitive information by reading log files.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.06
- Published: Nov. 08, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2013-0122
The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app.scanner.DeleteFileActivity with zer... Read more
Affected Products : avast\!_mobile_security- EPSS Score: %0.07
- Published: Apr. 22, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-2371
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1.1 allows local users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2010-2372.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.07
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2003-1399
eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.... Read more
Affected Products : eject- EPSS Score: %0.06
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2007-2580
Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script.... Read more
Affected Products : safari- EPSS Score: %0.26
- Published: May. 09, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-5292
Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.... Read more
Affected Products : amberdms_billing_system- EPSS Score: %0.06
- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2008-3876
Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a ... Read more
Affected Products : iphone- EPSS Score: %0.06
- Published: Sep. 02, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2009-5117
The Web Post Protection feature in McAfee Host Data Loss Prevention (DLP) 3.x before 3.0.100.10 and 9.x before 9.0.0.422, when HTTP Capture mode is enabled, allows local users to obtain sensitive information from web traffic by reading unspecified files.... Read more
Affected Products : host_data_loss_prevention- EPSS Score: %0.06
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-4832
Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, which makes it ea... Read more
- EPSS Score: %0.08
- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-1999-0078
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.... Read more
- EPSS Score: %0.14
- Published: Apr. 18, 1996
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2014-5233
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.... Read more
- EPSS Score: %0.06
- Published: Jan. 14, 2015
- Modified: Apr. 12, 2025