Latest CVE Feed
-
2.1
LOWCVE-2008-3067
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.... Read more
- EPSS Score: %0.06
- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-1984
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 5.x before 5.x-1.5 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the taxonom... Read more
- EPSS Score: %0.25
- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-1997
Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors.... Read more
Affected Products : pylon_anywhere- EPSS Score: %0.08
- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2011-1500
PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user's home directory, which allows local users to obtain Pandora credentials by reading this file.... Read more
Affected Products : pithos- EPSS Score: %0.05
- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-4835
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.... Read more
- EPSS Score: %0.05
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2025-43753
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through ... Read more
- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
2.1
LOWCVE-2011-2208
Integer signedness error in the osf_getdomainname function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform allows local users to obtain sensitive information from kernel memory via a crafted call.... Read more
Affected Products : linux_kernel- EPSS Score: %0.13
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-2105
Microsoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file.... Read more
Affected Products : windows_xp- EPSS Score: %0.39
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-6583
Cross-site scripting (XSS) vulnerability in the Imagemenu module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer imagemenu" permission to inject arbitrary web script or HTML via an image file name.... Read more
- EPSS Score: %0.34
- Published: Aug. 23, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-3978
SAP Sybase Unwired Platform Online Data Proxy allows local users to obtain usernames and passwords via the DataVault, aka SAP Security Note 2094830.... Read more
Affected Products : sybase_unwired_platform_online_data_proxy- EPSS Score: %0.06
- Published: May. 12, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-7128
Valve Bug Reporter in the valve-bugreporter package 2.10+bsos1 in Valve SteamOS Beta stores cleartext credentials in a .valve-bugreporter.cfg file upon a Remember Credentials action, which allows local users to obtain sensitive information by reading this... Read more
Affected Products : steamos- EPSS Score: %0.06
- Published: Dec. 17, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-1956
The create_user_ns function in kernel/user_namespace.c in the Linux kernel before 3.8.6 does not check whether a chroot directory exists that differs from the namespace root directory, which allows local users to bypass intended filesystem restrictions vi... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Apr. 24, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-4824
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.17
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-3379
Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the get_gate_vma function and the fuser command.... Read more
- EPSS Score: %0.06
- Published: Sep. 17, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-1970
The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere.... Read more
Affected Products : websphere_datapower_xc10_appliance_firmware- EPSS Score: %0.06
- Published: Aug. 03, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-0227
Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.... Read more
- EPSS Score: %0.20
- Published: Mar. 19, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2020-16237
Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.... Read more
- EPSS Score: %0.06
- Published: Aug. 21, 2020
- Modified: Jun. 04, 2025
-
2.1
LOWCVE-2014-4747
The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.... Read more
- EPSS Score: %0.06
- Published: Jul. 26, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-2072
Cross-site scripting (XSS) vulnerability in the Share Buttons (AddToAny) module 6.x-3.x before 6.x-3.4 for Drupal allows remote authenticated users with the administer addtoany permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.34
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-0503
IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.... Read more
Affected Products : websphere_message_broker- EPSS Score: %0.06
- Published: Feb. 13, 2009
- Modified: Apr. 09, 2025