Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2019-04-17 CVE-2019-9495 Information Exposure Through Discrepancy vulnerability in multiple products
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns.
3.7
2019-04-12 CVE-2019-11191 Race Condition vulnerability in Linux Kernel
The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat.
local
high complexity
linux CWE-362
2.5
2019-04-10 CVE-2019-6156 Improper Locking vulnerability in Lenovo products
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash.
local
low complexity
lenovo CWE-667
3.3
2019-04-09 CVE-2019-1573 Missing Encryption of Sensitive Data vulnerability in Paloaltonetworks Globalprotect 4.1.0/4.1.10
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.
local
high complexity
paloaltonetworks CWE-311
2.5
2019-04-03 CVE-2018-4470 Unspecified vulnerability in Apple mac OS X
A privacy issue in the handling of Open Directory records was addressed with improved indexing.
local
low complexity
apple
3.3
2019-04-03 CVE-2018-4446 Improper Input Validation vulnerability in Apple Iphone OS
This issue was addressed with improved entitlements.
local
low complexity
apple CWE-20
3.3
2019-04-03 CVE-2018-4430 Information Exposure vulnerability in Apple Iphone OS
A lock screen issue allowed access to contacts on a locked device.
low complexity
apple CWE-200
2.4
2019-04-03 CVE-2018-4387 Information Exposure vulnerability in Apple Iphone OS
A lock screen issue allowed access to photos via Reply With Message on a locked device.
low complexity
apple CWE-200
2.4
2019-04-03 CVE-2018-4352 Information Exposure vulnerability in Apple Iphone OS
A consistency issue existed in the handling of application snapshots.
local
low complexity
apple CWE-200
3.3
2019-04-03 CVE-2018-4325 Information Exposure vulnerability in Apple Iphone OS
A logic issue was addressed with improved restrictions.
low complexity
apple CWE-200
2.4