Latest CVE Feed
-
3.6
LOWCVE-2008-1371
Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the provenance of this information is unknown; the details a... Read more
Affected Products : drake_cms- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2013-2387
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 4.1.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to BASE.... Read more
Affected Products : financial_services_software- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2023-44129
The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity" activity. The attacker can abuse this functionality by... Read more
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
3.6
LOWCVE-2023-39342
Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzone CLI (`dangerzone-cli` command) logs output from the container where the file sanitization takes place, to the user's terminal. Prior... Read more
Affected Products : dangerzone- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
3.6
LOWCVE-2013-5857
Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authentic... Read more
Affected Products : industry_applications- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2006-4092
Simpliciti Locked Browser does not properly limit a user's actions to ones within the intended Internet Explorer environment, which allows local users to perform unauthorized actions by visiting a web site that executes a JavaScript window.blur loop to re... Read more
Affected Products : locked_browser- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2000-0121
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creation" vulnerability.... Read more
Affected Products : windows_nt- Published: Feb. 01, 2000
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-1999-1498
Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.... Read more
Affected Products : slackware_linux- Published: Apr. 06, 1998
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-1999-0828
UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.... Read more
Affected Products : unixware- Published: Dec. 02, 1999
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2004-1066
The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel me... Read more
Affected Products : freebsd- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-3786
Symantec pcAnywhere 12.5 uses weak integrity protection for .cif (aka caller or CallerID) files, which allows local users to generate a custom .cif file and modify the superuser flag.... Read more
Affected Products : pcanywhere- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2002-2334
Joe text editor 2.8 through 2.9.7 does not remove the group and user setuid bits for backup files, which could allow local users to execute arbitrary setuid and setgid root programs when root edits scripts owned by other users.... Read more
Affected Products : joe- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2009-3257
vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.... Read more
Affected Products : vtiger_crm- Published: Sep. 18, 2009
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2005-0288
The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.... Read more
Affected Products : webseries_payment_application- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2006-0202
Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50 and possibly earlier has (1) world-readable permissions for ipn/logs/ipn_success.txt, which allows local users to view sensitive information (payment data), and (2) world-writ... Read more
Affected Products : php_toolkit- Published: Jan. 13, 2006
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2007-2703
BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description, which might allow remote authenticated users to access privileged resources.... Read more
- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
3.6
LOWCVE-2001-1059
VMWare creates a temporary file vmware-log.USERNAME with insecure permissions, which allows local users to read or modify license information.... Read more
Affected Products : workstation- Published: Jul. 30, 2001
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2013-0412
Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect integrity and availability via unknown vectors related to Utility/pax.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-3738
The Emergency Dialer screen in the Passcode Lock implementation in Apple iOS before 6 does not properly limit the dialing methods, which allows physically proximate attackers to bypass intended access restrictions and make FaceTime calls through Voice Dia... Read more
Affected Products : iphone_os- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
3.6
LOWCVE-2012-3449
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.... Read more
Affected Products : openvswitch- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025