Latest CVE Feed
-
1.9
LOWCVE-2007-2873
SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by ... Read more
Affected Products : spamassassin- Published: Jun. 11, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2014-0076
The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.... Read more
Affected Products : openssl- Published: Mar. 25, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2007-0006
The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU... Read more
Affected Products : linux_kernel- Published: Feb. 06, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2014-0135
Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.... Read more
Affected Products : kafo- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2013-2168
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.... Read more
- Published: Jul. 03, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-2635
The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.... Read more
Affected Products : linux_kernel- Published: Mar. 22, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4081
The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSPM... Read more
- Published: Nov. 30, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2016-2943
IBM BigFix Remote Control before 9.1.3 allows local users to obtain sensitive information by leveraging unspecified privileges to read a log file.... Read more
Affected Products : bigfix_remote_control- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2013-1921
PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.... Read more
Affected Products : jboss_enterprise_application_platform- Published: Sep. 28, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-0154
The get_page_type function in xen/arch/x86/mm.c in Xen 4.2, when debugging is enabled, allows local PV or HVM guest administrators to cause a denial of service (assertion failure and hypervisor crash) via unspecified vectors related to a hypercall.... Read more
Affected Products : xen- Published: Jan. 12, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-2302
TransWARE Active! mail 6, when an external public interface is used, allows local users to obtain sensitive information belonging to arbitrary users by leveraging shell access, as demonstrated by a TELNET or SSH session to the server.... Read more
Affected Products : active\!_mail- Published: Apr. 04, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-4461
The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows local users to cause a denial of service (kernel OOPS) by using the KVM_SET_SREGS ioctl to set the X86_CR4_OSXSAVE bit in the guest cr4... Read more
Affected Products : linux_kernel- Published: Jan. 22, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-2162
Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with world-readable permissions before restricting the permissions, which allows local users... Read more
Affected Products : ubuntu_linux- Published: Aug. 19, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2010-4082
The viafb_ioctl_get_viafb_info function in drivers/video/via/ioctl.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memo... Read more
- Published: Nov. 30, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2015-1085
AppleKeyStore in Apple iOS before 8.3 does not properly restrict a certain passcode-confirmation interface, which makes it easier for attackers to verify correct passcode guesses via a crafted app.... Read more
Affected Products : iphone_os- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-1107
The Lock Screen component in Apple iOS before 8.3 does not properly implement the erasure feature for incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.... Read more
Affected Products : iphone_os- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-4450
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within uninte... Read more
Affected Products : iphone_os- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2013-4369
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.... Read more
Affected Products : xen- Published: Oct. 17, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-5187
The Screen Lock implementation in Apple Mac OS X before 10.9 does not immediately accept Keychain Status menu Lock Screen commands, and instead incorrectly relies on a certain timeout setting, which allows physically proximate attackers to obtain sensitiv... Read more
- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-6384
(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB passwo... Read more
Affected Products : ceilometer- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025