Latest CVE Feed
-
2.1
LOWCVE-2013-1822
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.8 allow remote authenticated users with administrator privileges to inject arbitrary web script or HTML via the (1) quota parameter to /core/settings/ajax/setquota.php, or re... Read more
- EPSS Score: %0.18
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-3337
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.... Read more
Affected Products : database_server- EPSS Score: %0.07
- Published: Jun. 22, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-6656
Unspecified vulnerability in ptrace in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read kernel memory and obtain sensitive information via certain manipulations of a PT_LWPINFO... Read more
Affected Products : netbsd- EPSS Score: %0.06
- Published: Dec. 20, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-6744
phpProfiles before 2.1.1 does not have an index.php or other index file in the (1) image_data, (2) graphics/comm, or (3) users read/write directories, which might allow remote attackers to list directory contents or have other unknown impacts.... Read more
Affected Products : phpprofiles- EPSS Score: %0.10
- Published: Dec. 26, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-0828
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.... Read more
Affected Products : aix- EPSS Score: %0.08
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1173
Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlin... Read more
Affected Products : wordperfect- EPSS Score: %0.14
- Published: Dec. 18, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-0259
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.... Read more
- EPSS Score: %0.18
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-4352
The securelevels implementation in NetBSD 2.1 and earlier, and Linux 2.6.15 and earlier, allows local users to bypass time setting restrictions and set the clock backwards by setting the clock ahead to the maximum unixtime value (19 Jan 2038), which then ... Read more
- EPSS Score: %0.11
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1407
ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.... Read more
Affected Products : linux- EPSS Score: %0.14
- Published: Mar. 09, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1409
The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.... Read more
- EPSS Score: %0.31
- Published: Jul. 03, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1430
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as... Read more
Affected Products : davinci- EPSS Score: %0.12
- Published: Jan. 01, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-7238
The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) configuration files and (2) installation logs, which allows local users to obtain sensitive information by reading the files.... Read more
Affected Products : threat_intelligence_exchange- EPSS Score: %0.04
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2000-0879
LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.... Read more
Affected Products : lpplus- EPSS Score: %0.06
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1499
named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.... Read more
Affected Products : bind- EPSS Score: %0.19
- Published: Apr. 10, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1540
shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code.... Read more
Affected Products : shell-lock- EPSS Score: %0.07
- Published: Oct. 04, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-5470
Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file.... Read more
Affected Products : expression_media- EPSS Score: %1.25
- Published: Oct. 16, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2000-0361
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.... Read more
Affected Products : suse_linux- EPSS Score: %0.09
- Published: Dec. 14, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-9418
The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users to cause a denial of service (memory overflow) via unspecified vectors.... Read more
Affected Products : espace_desktop- EPSS Score: %0.23
- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-6131
buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.... Read more
Affected Products : fedora_core- EPSS Score: %0.07
- Published: Nov. 26, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-1640
Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1... Read more
- EPSS Score: %0.25
- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025