Latest CVE Feed
-
4.0
MEDIUMCVE-2006-0174
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the ... Read more
- EPSS Score: %4.82
- Published: Jan. 11, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-4490
Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. (dot dot) sequence via the id parameter in (1) scripts/cbag/ag.exe or (... Read more
- EPSS Score: %6.30
- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0127
Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.... Read more
Affected Products : mailsite- EPSS Score: %1.30
- Published: Jan. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2004-1569
Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerAmp Music Converter 10.0 allows remote attackers to cause a denial of service or execute arbitrary code via a .pls or .m3u playlist that... Read more
- EPSS Score: %13.01
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3830
The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory. NOTE: because the uploaded... Read more
Affected Products : boastmachine- EPSS Score: %0.25
- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-6724
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of service (application crash) via a certain invalid PORT command.... Read more
Affected Products : dream_ftp_server- EPSS Score: %5.00
- Published: Dec. 26, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-3593
The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704.... Read more
Affected Products : unified_callmanager- EPSS Score: %0.58
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0613
Unspecified vulnerability in Java Web Start after 1.0.1_02, as used in J2SE 5.0 Update 5 and earlier, allows remote attackers to obtain privileges via unspecified vectors involving untrusted applications.... Read more
- EPSS Score: %3.24
- Published: Feb. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3859
IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands.... Read more
Affected Products : informix_dynamic_database_server- EPSS Score: %0.29
- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2008-5102
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.... Read more
Affected Products : zope- EPSS Score: %11.20
- Published: Nov. 17, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-5678
Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (... Read more
Affected Products : olib7_webview- EPSS Score: %2.80
- Published: Dec. 19, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2020-4164
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could expose sensitive information from applicatino errors which could be used in further attacks against the system. IBM X-Force ID: 174400.... Read more
Affected Products : security_information_queue- EPSS Score: %0.14
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-4706
IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. IBM X-Force ID: 172016.... Read more
Affected Products : security_identity_manager_virtual_appliance- EPSS Score: %0.14
- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2019-5461
An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.1... Read more
Affected Products : gitlab- EPSS Score: %0.08
- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-0516
Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.... Read more
- EPSS Score: %21.44
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-4965
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 f... Read more
Affected Products : maximo_asset_management maximo_for_life_sciences maximo_for_nuclear_power maximo_for_oil_and_gas maximo_for_transportation maximo_for_utilities smartcloud_control_desk change_and_configuration_management_database maximo_asset_management_essentials maximo_for_government +3 more products- EPSS Score: %0.15
- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-4263
The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.... Read more
- EPSS Score: %0.17
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-1982
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.... Read more
Affected Products : infosphere_master_data_management- EPSS Score: %0.16
- Published: Jul. 20, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-19420
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upl... Read more
- EPSS Score: %0.22
- Published: Nov. 21, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-0994
Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests.... Read more
Affected Products : ignition- EPSS Score: %0.25
- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025