Latest CVE Feed
-
4.0
MEDIUMCVE-2008-6658
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter duri... Read more
Affected Products : simple_machines_forum- EPSS Score: %1.15
- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-6199
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control.... Read more
Affected Products : 2532gigs- EPSS Score: %1.49
- Published: Feb. 20, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2005-4786
Buffer overflow in the archive decompression library (vrAZMain.dll 5.8.22.137), as used in HAURI anti-virus products including (1) ViRobot Expert 4.0, (2) ViRobot Advanced Server, and (3) HAURI LiveCall, allows user-assisted attackers to execute arbitrary... Read more
- EPSS Score: %1.45
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2019-4112
IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 158105.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.05
- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4132
IBM Cloud Automation Manager 3.1.2 could allow a user to be impropertly redirected and obtain sensitive information rather than receive a 404 error message. IBM X-Force ID: 158274.... Read more
Affected Products : cloud_automation_manager- EPSS Score: %0.09
- Published: Aug. 29, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-9156
The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file.... Read more
Affected Products : filefield- EPSS Score: %0.15
- Published: Dec. 01, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0863
The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authenticated users to obtain sensitive cleartext information via an unspecified ... Read more
Affected Products : cognos_tm1- EPSS Score: %0.20
- Published: Sep. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2006-1119
fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.... Read more
- EPSS Score: %0.18
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2014-6212
The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, ... Read more
Affected Products : emptoris_contract_management emptoris_program_management emptoris emptoris_sourcing_portfolio- EPSS Score: %0.21
- Published: Jan. 10, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3946
The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecified vectors.... Read more
Affected Products : typo3- EPSS Score: %0.15
- Published: Jun. 03, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3838
ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not properly check permissions, which allows remote authenticated users to read the names of files of other users by leveraging access to multiple accounts.... Read more
- EPSS Score: %0.13
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2008-7290
Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allows remote authenticated users to cause a denial of service (memory consumption) by making many function calls.... Read more
Affected Products : tivoli_directory_server- EPSS Score: %0.36
- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-3318
Directory traversal vulnerability in dna/viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup76318.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.68
- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3316
The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSCup76297.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.51
- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3132
SAP Background Processing does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1.... Read more
Affected Products : background_processing- EPSS Score: %0.25
- Published: Apr. 30, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2005-0253
Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.... Read more
Affected Products : biborb- EPSS Score: %5.52
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2018-1505
IBM i2 Enterprise Insight Analysis 2.1.7 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 141413.... Read more
Affected Products : i2_enterprise_insight_analysis- EPSS Score: %0.04
- Published: Dec. 06, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-1829
EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom... Read more
Affected Products : easerver- EPSS Score: %0.42
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2021-20391
IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.... Read more
- EPSS Score: %0.04
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4218
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 159227.... Read more
Affected Products : security_information_queue- EPSS Score: %0.04
- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024