Latest CVE Feed
-
2.1
LOWCVE-2010-3094
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxono... Read more
Affected Products : drupal- EPSS Score: %0.21
- Published: Sep. 21, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-1716
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.... Read more
Affected Products : safari- EPSS Score: %0.10
- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2011-4327
ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allows local users to obtain sensitive key information via the ptrace system call.... Read more
Affected Products : openssh- EPSS Score: %0.10
- Published: Feb. 03, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-2663
masqmail before 0.2.18 allows local users to overwrite arbitrary files via a symlink attack on a log file.... Read more
- EPSS Score: %0.10
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2656
Polygen before 1.0.6 generates precompiled grammar objects with world-writable permissions, which allows local users to cause a denial of service (disk consumption) and possibly perform other unauthorized activities.... Read more
Affected Products : polygen- EPSS Score: %0.04
- Published: Sep. 06, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2554
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.... Read more
Affected Products : epolicy_orchestrator_agent- EPSS Score: %0.05
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-2531
Microsoft Internet Information Services (IIS) 7.5 uses weak permissions for the Operational log, which allows local users to discover credentials by reading this file, aka "Password Disclosure Vulnerability."... Read more
- EPSS Score: %0.20
- Published: Nov. 14, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-5297
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic c... Read more
Affected Products : wordpress- EPSS Score: %0.27
- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0178
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directo... Read more
- EPSS Score: %0.05
- Published: Mar. 23, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0180
Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call.... Read more
- EPSS Score: %0.09
- Published: Mar. 23, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0279
HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to requi... Read more
Affected Products : multifunction_peripheral_digital_sending_software- EPSS Score: %0.08
- Published: Mar. 07, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2574
Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.... Read more
Affected Products : mantisbt- EPSS Score: %0.42
- Published: Aug. 10, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-1698
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote authenticated users to affect confidentiality, related to Kernel/GLD.... Read more
- EPSS Score: %0.26
- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-1004
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationNam... Read more
Affected Products : foswiki- EPSS Score: %0.26
- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-1828
usb-creator-helper in usb-creator before 0.2.28.3 does not enforce intended PolicyKit restrictions, which allows local users to perform arbitrary unmount operations via the UnmountFile method in a dbus-send command.... Read more
Affected Products : usb-creator- EPSS Score: %0.06
- Published: May. 16, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-0959
Remote Login Service (RLS) 1.0.0 does not properly clear account information when switching users, which might allow physically proximate users to obtain login credentials.... Read more
Affected Products : remote_login_service- EPSS Score: %0.07
- Published: Nov. 24, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-2451
Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.... Read more
- EPSS Score: %3.04
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-1923
RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x store passwords in cleartext under adm_b_db\users\, which allows local users to obtain sensitive information by reading a database.... Read more
- EPSS Score: %0.24
- Published: Apr. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-3735
The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amou... Read more
Affected Products : db2- EPSS Score: %0.41
- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-0948
DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials.... Read more
- EPSS Score: %0.05
- Published: Jun. 07, 2012
- Modified: Apr. 11, 2025