Latest CVE Feed
-
2.1
LOWCVE-2013-2047
The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password parameter, which makes it easier for physically proximate attackers to guess the password.... Read more
- EPSS Score: %0.06
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2025-32699
Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.... Read more
Affected Products : mediawiki- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-0318
useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.... Read more
Affected Products : webadmin- EPSS Score: %0.13
- Published: Jan. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-4039
ppc64-diag 2.6.1 uses 0775 permissions for /tmp/diagSEsnap and does not properly restrict permissions for /tmp/diagSEsnap/snapH.tar.gz, which allows local users to obtain sensitive information by reading files in this archive, as demonstrated by /var/log/... Read more
- EPSS Score: %0.06
- Published: Jun. 17, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-2210
The osf_getsysinfo function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform does not properly restrict the data size for GSI_GET_HWRPB operations, which allows local users to obtain sensitive information from kerne... Read more
Affected Products : linux_kernel- EPSS Score: %0.15
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-1630
Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.15
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-0346
SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process.... Read more
Affected Products : softremote_vpn_client- EPSS Score: %0.07
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2011-5187
Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified ve... Read more
- EPSS Score: %0.34
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1584
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.... Read more
- EPSS Score: %0.45
- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-2103
SQL injection vulnerability in MyBB (MyBulletinBoard) 1.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the (1) query string ($querystring variable) in (a) admin/adminlogs.php, which is not properly handled by adminfun... Read more
Affected Products : mybulletinboard- EPSS Score: %0.35
- Published: Apr. 29, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1808
Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : metamail- EPSS Score: %0.07
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2205
The audio_write function in NetBSD 3.0 allows local users to cause a denial of service (kernel crash) by using the audiosetinfo ioctl to change the sample rate of an audio device.... Read more
Affected Products : netbsd- EPSS Score: %0.07
- Published: May. 05, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0624
reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.... Read more
Affected Products : reportbug- EPSS Score: %0.06
- Published: Feb. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-2343
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of service (excessive data processing) via a crafted DNP request over a serial line.... Read more
Affected Products : scada_data_gateway- EPSS Score: %0.06
- Published: May. 30, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0647
The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-m... Read more
- EPSS Score: %0.08
- Published: Jan. 28, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-2221
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitro... Read more
- EPSS Score: %0.07
- Published: May. 05, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2011-3536
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to DTrace Software Library (libdtrace).... Read more
Affected Products : solaris- EPSS Score: %0.14
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-4303
Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme 7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users with the Administer themes permission to inject arbitrary web script or HTML via vectors related to the (1) Twitter a... Read more
Affected Products : touch- EPSS Score: %0.37
- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-4548
IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (daemon crash) by accepting a meeting invitation with an iNotes client and then accepting this meeting invitation with an iPhone client.... Read more
- EPSS Score: %0.41
- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-5231
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors.... Read more
- EPSS Score: %0.06
- Published: Jan. 14, 2015
- Modified: Apr. 12, 2025