Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 2.1

    LOW
    CVE-2013-6387

    Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.... Read more

    Affected Products : drupal
    • EPSS Score: %0.16
    • Published: Dec. 24, 2013
    • Modified: Apr. 11, 2025
  • 2.1

    LOW
    CVE-2010-3850

    The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl ... Read more

    • EPSS Score: %0.09
    • Published: Dec. 30, 2010
    • Modified: Apr. 11, 2025
  • 2.1

    LOW
    CVE-2013-4064

    Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTH... Read more

    Affected Products : lotus_inotes lotus_domino
    • EPSS Score: %0.17
    • Published: Dec. 21, 2013
    • Modified: Apr. 11, 2025
  • 2.1

    LOW
    CVE-2015-6102

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection ... Read more

    • EPSS Score: %3.68
    • Published: Nov. 11, 2015
    • Modified: Apr. 12, 2025
  • 2.1

    LOW
    CVE-2006-2289

    Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execute arbitrary code via unknown vectors.... Read more

    Affected Products : avahi
    • EPSS Score: %0.12
    • Published: May. 10, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0458

    L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.... Read more

    Affected Products : l0phtcrack
    • EPSS Score: %0.13
    • Published: Jan. 06, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0483

    OpenBSD crash using nlink value in FFS and EXT2FS filesystems.... Read more

    Affected Products : openbsd
    • EPSS Score: %0.08
    • Published: Feb. 25, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2000-0067

    CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.... Read more

    Affected Products : merchant_connection_kit
    • EPSS Score: %0.12
    • Published: Jan. 11, 2000
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0372

    The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.... Read more

    Affected Products : windows_2000 windows_nt backoffice
    • EPSS Score: %4.75
    • Published: Feb. 12, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-1538

    When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's pas... Read more

    Affected Products : internet_information_server
    • EPSS Score: %56.60
    • Published: Jan. 14, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2014-3425

    NCSA Mosaic 2.0 and earlier allows local users to cause a denial of service ("remote control" outage) by creating a /tmp/xmosaic.pid file for every possible PID.... Read more

    Affected Products : ncsa_mosaic
    • EPSS Score: %0.05
    • Published: May. 08, 2014
    • Modified: Apr. 12, 2025
  • 2.1

    LOW
    CVE-2000-0633

    Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.... Read more

    Affected Products : linux linux mandrake_linux
    • EPSS Score: %0.06
    • Published: Jul. 18, 2000
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0367

    NetBSD netstat command allows local users to access kernel memory.... Read more

    Affected Products : netbsd
    • EPSS Score: %0.12
    • Published: Feb. 09, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2000-0263

    The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.... Read more

    Affected Products : linux
    • EPSS Score: %0.48
    • Published: Apr. 16, 2000
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0322

    The open() function in FreeBSD allows local attackers to write to arbitrary files.... Read more

    Affected Products : freebsd
    • EPSS Score: %0.11
    • Published: Oct. 29, 1997
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2000-0402

    The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.... Read more

    Affected Products : sql_server
    • EPSS Score: %78.48
    • Published: May. 30, 2000
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0851

    Denial of service in BIND named via naptr.... Read more

    Affected Products : aix sunos unixware openserver
    • EPSS Score: %0.09
    • Published: Nov. 10, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2000-0293

    aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp direct... Read more

    Affected Products : suse_linux
    • EPSS Score: %0.18
    • Published: May. 02, 2000
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-1065

    tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.... Read more

    Affected Products : linux_desktop
    • EPSS Score: %0.04
    • Published: May. 02, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0857

    FreeBSD gdc program allows local users to modify files via a symlink attack.... Read more

    Affected Products : freebsd
    • EPSS Score: %0.15
    • Published: Dec. 01, 1999
    • Modified: Apr. 03, 2025
Showing 20 of 291712 Results