Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4419 | LOW | Patched | 1.9 | 2014-09-18 | The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive m… |
| CVE-2014-4420 | LOW | Patched | 1.9 | 2014-09-18 | The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive m… |
| CVE-2014-4421 | LOW | Patched | 1.9 | 2014-09-18 | The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive m… |
| CVE-2014-4371 | LOW | Patched | 1.9 | 2014-09-18 | The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive m… |
| CVE-2014-4384 | LOW | Patched | 1.9 | 2014-09-18 | Directory traversal vulnerability in the App Installation feature in Apple iOS before 8 allows local users to install unverified apps by triggering code-signature validatio… |
| CVE-2014-4386 | LOW | Patched | 1.9 | 2014-09-18 | Race condition in the App Installation feature in Apple iOS before 8 allows local users to gain privileges and install unverified apps by leveraging /tmp write access. |
| CVE-2014-5036 | LOW | Patched | 1.9 | 2014-09-05 | The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local u… |
| CVE-2014-0974 | LOW | 1.9 | 2014-08-25 | The boot_linux_from_mmc function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for … | |
| CVE-2014-0179 | LOW | Patched | 1.9 | 2014-08-03 | libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity … |
| CVE-2014-5030 | LOW | Patched | 1.9 | 2014-07-29 | CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py. |
| CVE-2014-4652 | LOW | Patched | 1.9 | 2014-07-03 | Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before … |
| CVE-2014-1352 | LOW | Patched | 1.9 | 2014-07-01 | Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct b… |
| CVE-2014-3956 | LOW | Patched | 1.9 | 2014-06-04 | The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows l… |
| CVE-2014-3716 | LOW | 1.9 | 2014-05-19 | Xen 4.4.x does not properly check alignment, which allows local users to cause a denial of service (crash) via an unspecified field in a DTB header in a 32-bit guest kernel. | |
| CVE-2014-0135 | LOW | Patched | 1.9 | 2014-05-08 | Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and oth… |
| CVE-2013-7336 | LOW | Patched | 1.9 | 2014-05-07 | The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which al… |
| CVE-2014-2893 | LOW | Patched | 1.9 | 2014-04-23 | The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink … |
| CVE-2011-3154 | LOW | Patched | 1.9 | 2014-04-17 | DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.… |
| CVE-2014-1515 | LOW | Patched | 1.9 | 2014-03-25 | Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Fir… |
| CVE-2014-0076 | LOW | Patched | 1.9 | 2014-03-25 | The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local u… |
| CVE-2014-0017 | LOW | Patched | 1.9 | 2014-03-14 | The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which cause… |
| CVE-2014-1281 | LOW | Patched | 1.9 | 2014-03-14 | Photos Backend in Apple iOS before 7.1 does not properly manage the asset-library cache during deletions, which allows physically proximate attackers to obtain sensitive ph… |
| CVE-2011-3153 | LOW | Patched | 1.9 | 2014-03-06 | dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink attack on ~/.dmrc. |
| CVE-2014-0890 | LOW | 1.9 | 2014-03-06 | The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, 8.5.2.1, 9.0, and 9.0.0.1, when a certain com.ibm.collaboration.realtime.telephony.*.level setting is use… | |
| CVE-2014-0058 | LOW | Patched | 1.9 | 2014-02-26 | The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users… |