Latest CVE Feed
-
1.9
LOWCVE-2007-3849
Red Hat Enterprise Linux (RHEL) 5 ships the rpm for the Advanced Intrusion Detection Environment (AIDE) before 0.13.1 with a database that lacks checksum information, which allows context-dependent attackers to bypass file integrity checks and modify cert... Read more
Affected Products : enterprise_linux- Published: Sep. 05, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2023-31305
Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Nov. 06, 2024
-
1.9
LOWCVE-2005-1488
Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.ht... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2024-53855
Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management (ITSM) modules. A user who is authenticated and has view permissions for a ticket, can ... Read more
Affected Products : centurion_erp- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
1.9
LOWCVE-2007-5143
F-Secure Anti-Virus for Windows Servers 7.0 64-bit edition allows local users to bypass virus scanning by using the system32 directory to store a crafted (1) archive or (2) packed executable. NOTE: in many environments, this does not cross privilege boun... Read more
- Published: Oct. 01, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2023-20518
Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Nov. 05, 2024
-
1.9
LOWCVE-2010-2027
Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.... Read more
- Published: May. 24, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-0473
The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.... Read more
Affected Products : smb4k- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2009-2911
SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel... Read more
Affected Products : systemtap- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-4212
The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data.... Read more
- Published: Nov. 09, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-4972
RegMon 7.04 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks to the (1) NtCreateKey ... Read more
Affected Products : regmon- Published: Sep. 19, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-2470
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files ... Read more
Affected Products : bugzilla- Published: Jun. 28, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2014-2893
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directories with predictable names.... Read more
- Published: Apr. 23, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2009-1296
The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk. NOTE: the log files are on... Read more
- Published: Jun. 09, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2007-0822
umount, when running with the Linux 2.6.15 kernel on Slackware Linux 10.2, allows local users to trigger a NULL dereference and application crash by invoking the program with a pathname for a USB pen drive that was mounted and then physically removed, whi... Read more
Affected Products : linux_kernel- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2011-4029
The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a ... Read more
Affected Products : x_server- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-5438
Unspecified vulnerability in a certain ActiveX control in Reconfig.DLL in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 b... Read more
- Published: Oct. 13, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2007-3850
The eHCA driver in Linux kernel 2.6 before 2.6.22, when running on PowerPC, does not properly map userspace resources, which allows local users to read portions of physical address space.... Read more
- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2014-4421
The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different ... Read more
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2025-58156
Centurion ERP is an ERP with a focus on ITSM and automation. In versions starting from 1.12.0 to before 1.21.0, an authenticated user can view all authentication token details within the database. This includes the actual token, although only the hashed t... Read more
Affected Products : centurion_erp- Published: Aug. 29, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Information Disclosure