Latest CVE Feed
-
2.1
LOWCVE-2012-2284
The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspe... Read more
- Published: Oct. 18, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-1933
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by... Read more
- Published: Apr. 17, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2025-22149
JWK Set (JSON Web Key Set) is a JWK and JWK Set Go implementation. Prior to 0.6.0, the project's provided HTTP client's local JWK Set cache should do a full replacement when the goroutine refreshes the remote JWK Set. The current behavior is to overwrite ... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
2.1
LOWCVE-2014-4446
Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a change made by an admin... Read more
Affected Products : os_x_server- Published: Oct. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-6488
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform: 10.2.0.5, 11.1.0.1 EM DB Control: 11.1.0.7, 11.2.0.3, 11.2.0.4 EM Plugin for DB: 12.1.0.4, 12.1.0.5, and 12.1.0.6... Read more
Affected Products : enterprise_manager enterprise_manager_grid_control enterprise_manager_database_control- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-3813
A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.... Read more
Affected Products : enterprise_linux- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-3099
usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of se... Read more
Affected Products : enterprise_linux- Published: Jun. 14, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-5892
Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.... Read more
Affected Products : iphone_os- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-1069
Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.... Read more
- Published: Feb. 17, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-6654
The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a failure to retrieve a reference on a foreign page, which allows remote domains to cause a denial... Read more
Affected Products : xen- Published: Sep. 03, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-6807
Cross-site scripting (XSS) vulnerability in the Mass Contact module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer mass contact" permission to inject arbitrary web script or HTML via a c... Read more
Affected Products : mass_contact- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5448
HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : asset_manager- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5748
The kernel in Apple OS X before 10.10.5 does not properly mount HFS volumes, which allows local users to cause a denial of service via a crafted volume.... Read more
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5742
VeeamVixProxy in Veeam Backup & Replication (B&R) before 8.0 update 3 stores local administrator credentials in log files with world-readable permissions, which allows local users to obtain sensitive information by reading the files.... Read more
- Published: Oct. 16, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-2494
kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.... Read more
Affected Products : linux_kernel- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-1438
The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.... Read more
Affected Products : subversion- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-5697
The get_bitmap_file function in drivers/md/md.c in the Linux kernel before 4.1.6 does not initialize a certain bitmap data structure, which allows local users to obtain sensitive information from kernel memory via a GET_BITMAP_FILE ioctl call.... Read more
Affected Products : linux_kernel- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-0706
Bugzilla 2.17.5 through 2.17.7 embeds the password in an image URL, which could allow local users to view the password in the web server log files.... Read more
Affected Products : bugzilla- Published: Jul. 27, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1845
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file... Read more
- Published: May. 02, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-4747
Unspecified vulnerability in the search feature in Sun Java System LDAP JDK before 4.20 allows context-dependent attackers to obtain sensitive information via unknown attack vectors related to the LDAP JDK library.... Read more
- Published: Oct. 27, 2008
- Modified: Apr. 09, 2025