Latest CVE Feed
-
2.1
LOWCVE-2014-5448
Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by reading the log files.... Read more
Affected Products : zarafa- Published: Oct. 20, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-5619
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activit... Read more
Affected Products : the_sleuth_kit- Published: Sep. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-4460
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cach... Read more
- Published: Nov. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-1589
TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user.... Read more
- Published: Mar. 21, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-3107
The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clea... Read more
Affected Products : linux_kernel- Published: Jul. 10, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-5770
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Locking.... Read more
Affected Products : mysql- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-3379
Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the get_gate_vma function and the fuser command.... Read more
- Published: Sep. 17, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-4357
Accounts Framework in Apple iOS before 8 and Apple TV before 7 allows attackers to obtain sensitive information by reading log data that was not intended to be present in a log.... Read more
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4143
The (1) checkPasswd and (2) checkGroupXlockPasswds functions in xlockmore before 5.43 do not properly handle when a NULL value is returned upon an error by the crypt or dispcrypt function as implemented in glibc 2.17 and later, which allows attackers to b... Read more
Affected Products : xlockmore- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-3106
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than... Read more
Affected Products : fusion_middleware- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-3074
SSL_Cipher.cpp in EncFS before 1.7.0 uses an improper combination of an AES cipher and a CBC cipher mode for encrypted filesystems, which allows local users to obtain sensitive information via a watermark attack.... Read more
Affected Products : encfs- Published: Sep. 17, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-0010
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.... Read more
Affected Products : linux_kernel- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-2797
xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.... Read more
- Published: Aug. 27, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-2691
The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.... Read more
Affected Products : linux_kernel- Published: Aug. 14, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-2087
The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation,... Read more
Affected Products : websphere_application_server- Published: Aug. 13, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-0518
VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password.... Read more
- Published: Apr. 06, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-2089
The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a M... Read more
Affected Products : websphere_application_server- Published: Aug. 13, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-3875
The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structur... Read more
- Published: Jan. 03, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-5851
The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.... Read more
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-3201
Thermostat before 2.0.0 uses world-readable permissions for the web.xml configuration file, which allows local users to obtain user credentials by reading the file.... Read more
Affected Products : thermostat- Published: Jun. 08, 2015
- Modified: Apr. 12, 2025