Search
15,635 CVEs · Low severity
CVEs (15,635, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 15,635 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-0018 | LOW | 1.9 | 2014-02-14 | Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the … | |
| CVE-2014-0019 | LOW | 1.9 | 2014-02-04 | Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long s… | |
| CVE-2014-1446 | LOW | Patched | 1.9 | 2014-01-18 | The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain se… |
| CVE-2010-5292 | LOW | Patched | 1.9 | 2014-01-10 | Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache i… |
| CVE-2013-4509 | LOW | Patched | 1.9 | 2013-11-23 | The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered pass… |
| CVE-2013-0223 | LOW | 1.9 | 2013-11-23 | The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join… | |
| CVE-2013-6384 | LOW | Patched | 1.9 | 2013-11-23 | (1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, … |
| CVE-2013-4481 | LOW | 1.9 | 2013-11-23 | Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the fi… | |
| CVE-2013-4425 | LOW | Patched | 1.9 | 2013-11-18 | The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which … |
| CVE-2013-3287 | LOW | Patched | 1.9 | 2013-11-02 | EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind passw… |
| CVE-2013-4469 | LOW | 1.9 | 2013-11-02 | OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to ca… | |
| CVE-2013-1056 | LOW | 1.9 | 2013-10-28 | X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files. | |
| CVE-2013-5187 | LOW | Patched | 1.9 | 2013-10-24 | The Screen Lock implementation in Apple Mac OS X before 10.9 does not immediately accept Keychain Status menu Lock Screen commands, and instead incorrectly relies on a cert… |
| CVE-2013-5169 | LOW | Patched | 1.9 | 2013-10-24 | CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that screen locking blocks the visibility of all windows, which allows physical… |
| CVE-2013-4368 | LOW | Patched | 1.9 | 2013-10-17 | The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allo… |
| CVE-2013-4369 | LOW | 1.9 | 2013-10-17 | The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" cha… | |
| CVE-2013-1921 | LOW | Patched | 1.9 | 2013-09-28 | PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file. |
| CVE-2013-4025 | LOW | Patched | 1.9 | 2013-09-25 | IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do … |
| CVE-2013-5150 | LOW | Patched | 1.9 | 2013-09-19 | The history-clearing feature in Safari in Apple iOS before 7 does not clear the back/forward history of an open tab, which allows physically proximate attackers to obtain s… |
| CVE-2013-4259 | LOW | Patched | 1.9 | 2013-09-16 | runner/connection_plugins/ssh.py in Ansible before 1.2.3, when using ControlPersist, allows local users to redirect a ssh session via a symlink attack on a socket file with… |
| CVE-2013-2898 | LOW | Patched | 1.9 | 2013-09-16 | drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proxim… |
| CVE-2013-2976 | LOW | Patched | 1.9 | 2013-08-21 | The Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0 does not properly … |
| CVE-2013-4242 | LOW | Patched | 1.9 | 2013-08-19 | GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel a… |
| CVE-2013-2162 | LOW | 1.9 | 2013-08-19 | Race condition in the post-installation script (mysql-server-5.5.postinst) for MySQL Server 5.5 for Debian GNU/Linux and Ubuntu Linux creates a configuration file with worl… | |
| CVE-2013-2168 | LOW | Patched | 1.9 | 2013-07-03 | The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local u… |