Latest CVE Feed
-
2.1
LOWCVE-2014-0201
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files.... Read more
Affected Products : rhevm-reports- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6402
base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file.... Read more
Affected Products : linux_imaging_and_printing_project- Published: Jan. 05, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2141
The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted application that makes a (1) tkill or (2) tgk... Read more
Affected Products : linux_kernel- Published: Jun. 07, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0181
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations... Read more
- Published: Apr. 27, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-5872
Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to Name Service Cache Daemon (NSCD).... Read more
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2148
The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on th... Read more
Affected Products : linux_kernel- Published: Jun. 07, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-6493
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.... Read more
Affected Products : icedtea-web- Published: Mar. 03, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-2190
The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.... Read more
Affected Products : cherokee- Published: Oct. 07, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-4537
Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion f... Read more
Affected Products : xen- Published: Nov. 21, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-6116
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.... Read more
- Published: Mar. 01, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-7064
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML vi... Read more
Affected Products : eu_cookie_compliance- Published: Apr. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-5066
The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC)... Read more
Affected Products : websphere_application_server- Published: Jan. 15, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0711
The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V... Read more
- Published: Mar. 01, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0199
The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allows local users to obtain sensitive information by reading... Read more
Affected Products : rhevm-reports- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2009-0368
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer ... Read more
Affected Products : opensc- Published: Mar. 02, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-0202
The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database password in cleartext, which allows local users to obtain sensitive information by ... Read more
Affected Products : rhevm-dwh- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9584
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memo... Read more
- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6956
Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4 before 7.4r6, and 8.0 before 8.0r1, when web rewrite is... Read more
Affected Products : ive_os- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2096
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not ... Read more
- Published: Jul. 09, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-1771
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than... Read more
Affected Products : fusion_middleware- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025