Latest CVE Feed
-
2.1
LOWCVE-2015-6375
The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an unspecified file, aka Bug ID CSCux18010.... Read more
Affected Products : ios- EPSS Score: %0.06
- Published: Nov. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-1999-1406
dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.... Read more
Affected Products : linux- EPSS Score: %0.08
- Published: Jul. 29, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0489
FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.... Read more
- EPSS Score: %1.05
- Published: Sep. 05, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1408
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different... Read more
- EPSS Score: %0.25
- Published: Mar. 05, 1997
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0559
eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.... Read more
Affected Products : etrust_intrusion_detection- EPSS Score: %0.12
- Published: Jun. 07, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0565
SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.... Read more
Affected Products : smartftp_daemon- EPSS Score: %0.10
- Published: Jun. 13, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-1281
cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.... Read more
Affected Products : cgihtml- EPSS Score: %0.18
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6696
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php. NOTE: vector 1... Read more
Affected Products : webcalendar- EPSS Score: %0.41
- Published: Feb. 01, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-0996
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it ea... Read more
- EPSS Score: %0.06
- Published: Mar. 29, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-2263
Unspecified vulnerability in Sun Integrated Lights Out Manager in Oracle SysFW 8.0.3.b or earlier for various Oracle SPARC T3, SPARC Netra T3, Sun Blade, and Sun Fire servers allows local users to affect confidentiality via unknown vectors.... Read more
Affected Products : sysfw netra_sparc_t3-1 sparc_t3-1 sparc_t3-1b sparc_t3-3 sparc_t3-4 sun_blade_x6250 sun_blade_x6270 sun_blade_x6270_m2 sun_blade_x6275 +13 more products- EPSS Score: %0.45
- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2000-0311
The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability.... Read more
Affected Products : windows_2000- EPSS Score: %0.65
- Published: Apr. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6434
Linux kernel 2.6.23 allows local users to create low pages in virtual userspace memory and bypass mmap_min_addr protection via a crafted executable file that calls the do_brk function.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Dec. 18, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-1487
IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.... Read more
- EPSS Score: %0.06
- Published: Apr. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-0622
Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive inform... Read more
Affected Products : mac_os_x- EPSS Score: %0.12
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4589
Spb Kiosk Engine 1.0.0.1 stores the administrator's passcode in the registry in plaintext, which allows local users to obtain the passcode.... Read more
Affected Products : kiosk_engine- EPSS Score: %0.08
- Published: Dec. 30, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0445
The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.... Read more
Affected Products : pgp- EPSS Score: %0.26
- Published: May. 24, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0881
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.... Read more
Affected Products : lpplus- EPSS Score: %0.15
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0485
Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.... Read more
Affected Products : sql_server- EPSS Score: %1.27
- Published: May. 30, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4691
imake in NetBSD before 2.0.3, NetBSD-current before 12 September 2005, certain versions of X.Org, and certain versions of XFree86 allows local users to overwrite arbitrary files via a symlink attack on the temporary file for the file.0 target, which is us... Read more
Affected Products : netbsd- EPSS Score: %0.08
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0076
nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.... Read more
- EPSS Score: %0.10
- Published: Dec. 30, 1999
- Modified: Apr. 03, 2025