Latest CVE Feed
-
2.1
LOWCVE-2006-0369
MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that... Read more
Affected Products : mysql- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-7080
Siri in Apple iOS before 9.2 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.... Read more
Affected Products : iphone_os- Published: Dec. 11, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-3257
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the same mail server, which allows local users to bypass intended access restrictions in opportunistic circumstances by leveraging a differ... Read more
Affected Products : iphone_os- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-2489
Unspecified vulnerability in the utdmsession program in Sun Ray Server Software (SRSS) 4.0 allows local users to access the sessions of arbitrary users via unknown vectors.... Read more
Affected Products : ray_server_software- Published: Jul. 16, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-0980
The Passcode Lock implementation in Apple iOS before 6.1.3 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging an error in the emergency-call feature.... Read more
Affected Products : iphone_os- Published: Mar. 20, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-7835
webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site... Read more
Affected Products : moodle- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2008-7261
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which might allow local users to obtain sensitive information by reading this fil... Read more
Affected Products : filenet_p8_application_engine- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-6191
Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries.... Read more
Affected Products : swimage_encore- Published: Feb. 19, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-5912
An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a ... Read more
Affected Products : internet_explorer- Published: Jan. 20, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-4870
dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.... Read more
- Published: Nov. 01, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-6756
ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.... Read more
- Published: Apr. 27, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-5915
An unspecified function in the JavaScript implementation in Google Chrome creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up... Read more
Affected Products : chrome- Published: Jan. 20, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-0013
dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.... Read more
- Published: Feb. 13, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-7258
The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins with a . (dot) character. NOTE: CVE disputes this issue be... Read more
Affected Products : ssmtp- Published: Aug. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-5240
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted... Read more
- Published: Aug. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2008-1945
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, ... Read more
- Published: Aug. 08, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-4455
dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file.... Read more
- Published: Nov. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-2284
The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspe... Read more
- Published: Oct. 18, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-4463
Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or transmit a Photo Library photo, via the FaceTime "Leave a Message" feature.... Read more
Affected Products : iphone_os- Published: Nov. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5247
The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API ... Read more
- Published: Aug. 29, 2014
- Modified: Apr. 12, 2025