Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1085 | LOW | Patched | 1.9 | 2015-04-10 | AppleKeyStore in Apple iOS before 8.3 does not properly restrict a certain passcode-confirmation interface, which makes it easier for attackers to verify correct passcode g… |
| CVE-2014-8923 | LOW | Patched | 1.9 | 2015-03-25 | The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Ide… |
| CVE-2015-2152 | LOW | Patched | 1.9 | 2015-03-18 | Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local g… |
| CVE-2015-1420 | LOW | Patched | 1.9 | 2015-03-16 | Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read op… |
| CVE-2015-1064 | LOW | Patched | 1.9 | 2015-03-12 | Springboard in Apple iOS before 8.2 allows physically proximate attackers to bypass an intended activation requirement and read the home screen by leveraging an application… |
| CVE-2015-1197 | LOW | 1.9 | 2015-02-19 | cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive. | |
| CVE-2014-6195 | LOW | Patched | 1.9 | 2015-02-14 | The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5… |
| CVE-2015-0245 | LOW | Patched | 1.9 | 2015-02-13 | D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to… |
| CVE-2015-0010 | LOW | 1.9 | 2015-02-11 | The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2,… | |
| CVE-2015-0430 | LOW | 1.9 | 2015-01-21 | Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality via vectors related to RPC Utility. | |
| CVE-2015-0413 | LOW | 1.9 | 2015-01-21 | Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability. | |
| CVE-2014-5233 | LOW | Patched | 1.9 | 2015-01-14 | The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the crede… |
| CVE-2014-5232 | LOW | Patched | 1.9 | 2015-01-14 | The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the ap… |
| CVE-2015-0001 | LOW | 1.9 | 2015-01-13 | The Windows Error Reporting (WER) component in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to bypass t… | |
| CVE-2014-9415 | LOW | Patched | 1.9 | 2014-12-24 | Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QES file. |
| CVE-2014-7170 | LOW | 1.9 | 2014-12-17 | Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service. | |
| CVE-2014-8595 | LOW | 1.9 | 2014-11-19 | arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of… | |
| CVE-2014-6146 | LOW | 1.9 | 2014-11-08 | IBM Sterling B2B Integrator 5.2.x through 5.2.4, when the Connect:Direct Server Adapter is configured, does not properly process the logging configuration, which allows loc… | |
| CVE-2014-3636 | LOW | Patched | 1.9 | 2014-10-25 | D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by qu… |
| CVE-2014-4448 | LOW | Patched | 1.9 | 2014-10-22 | House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive informa… |
| CVE-2014-4450 | LOW | Patched | 1.9 | 2014-10-22 | The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easi… |
| CVE-2014-5423 | LOW | Patched | 1.9 | 2014-10-19 | CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 allows local users to obtain potentially sensitive information by reading a temporary (1) debugging… |
| CVE-2014-4822 | LOW | Patched | 1.9 | 2014-10-19 | IBM WebSphere MQ classes for Java libraries 8.0 before 8.0.0.1 and Websphere MQ Explorer 7.5 before 7.5.0.5 and 8.0 before 8.0.0.2 allow local users to discover preconfigur… |
| CVE-2014-4447 | LOW | Patched | 1.9 | 2014-10-18 | Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file after a (1) profile setup or (2) profile edit occurs. |
| CVE-2014-6540 | LOW | Patched | 1.9 | 2014-10-15 | Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.34, before 4.2.26, and before 4.3.14 allows local users to af… |