Latest CVE Feed
-
2.1
LOWCVE-2015-2044
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly initialize data, which allow local HVM guest users to obtain sensitive information via vectors involving an unsupported access size.... Read more
Affected Products : xen- Published: Mar. 12, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-4536
The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to cause a denial of service (Xen crash) via a crafted pirq value that triggers an out-of-bounds read.... Read more
Affected Products : xen- Published: Nov. 21, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-5040
Ghost Security Suite alpha 1.200 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey,... Read more
Affected Products : ghost_security_suite- Published: Sep. 24, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-1322
QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.... Read more
- Published: May. 02, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-1563
The ARM GIC distributor virtualization in Xen 4.4.x and 4.5.x allows local guests to cause a denial of service by causing a large number messages to be logged.... Read more
- Published: Feb. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-5619
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activit... Read more
Affected Products : the_sleuth_kit- Published: Sep. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-5770
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.... Read more
Affected Products : mysql- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-3337
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.... Read more
Affected Products : database_server- Published: Jun. 22, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-3201
Thermostat before 2.0.0 uses world-readable permissions for the web.xml configuration file, which allows local users to obtain user credentials by reading the file.... Read more
Affected Products : thermostat- Published: Jun. 08, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-3379
Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the get_gate_vma function and the fuser command.... Read more
- Published: Sep. 17, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-6394
Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.... Read more
- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-0418
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than C... Read more
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2001-0275
Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.... Read more
Affected Products : netsuite_web_server- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0787
The SSH authentication agent follows symlinks via a UNIX domain socket.... Read more
Affected Products : ssh- Published: Sep. 17, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0384
ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.... Read more
Affected Products : reliant_unix- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0265
ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.... Read more
Affected Products : pgp- Published: Jun. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0803
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.... Read more
Affected Products : aix_enetwork_firewall- Published: May. 25, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0595
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.... Read more
- Published: Jan. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0461
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.... Read more
- Published: May. 29, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0310
sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scripts.... Read more
Affected Products : freebsd- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025