Latest CVE Feed
-
2.1
LOWCVE-2010-1997
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.... Read more
Affected Products : saurus_cms- EPSS Score: %0.46
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-3722
The 4BSD process scheduler in the FreeBSD kernel performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that... Read more
Affected Products : freebsd- EPSS Score: %0.06
- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-5456
Cross-site scripting (XSS) vulnerability in the Social Stats module before 7.x-1.5 for Drupal allows remote authenticated users with the "[Content Type]: Create new content" permission to inject arbitrary web script or HTML via vectors related to the conf... Read more
Affected Products : social_stats- EPSS Score: %0.20
- Published: Aug. 25, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-3720
The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that re... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-1976
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb dis... Read more
- EPSS Score: %0.25
- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-6267
Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.... Read more
Affected Products : edgesight_for_endpoints edgesight_for_netscaler edgesight_for_presentation_server- EPSS Score: %0.08
- Published: Dec. 07, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-1844
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.... Read more
- EPSS Score: %0.07
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-3706
The _sanitize_globals function in CodeIgniter 1.5.3 before 20070628 allows remote attackers to unset arbitrary global variables with unspecified impact, as demonstrated by a _SERVER cookie.... Read more
Affected Products : codeigniter- EPSS Score: %0.16
- Published: Jul. 11, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-2796
The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password.... Read more
Affected Products : iphone_os- EPSS Score: %0.07
- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-2159
Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information.... Read more
Affected Products : internet_explorer- EPSS Score: %0.84
- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-2002
Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with "administer words filtered" privileges, to inject arbitrary web script or HTML via the word list... Read more
- EPSS Score: %0.23
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-2314
Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to overwrite arbitrary files via unspecified vectors.... Read more
- EPSS Score: %0.07
- Published: Jul. 05, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-5701
Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "ca un... Read more
Affected Products : lotus_domino- EPSS Score: %0.05
- Published: Oct. 29, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-5417
HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) S... Read more
- EPSS Score: %0.08
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-7207
RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php.... Read more
Affected Products : rivettracker- EPSS Score: %0.06
- Published: Sep. 11, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-5827
iSCSI Enterprise Target (iscsitarget) 0.4.15 uses weak permissions for /etc/ietd.conf, which allows local users to obtain passwords.... Read more
- EPSS Score: %0.05
- Published: Nov. 05, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-0988
Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project source-code files, which makes it easier for local users to obtain sensitive information by reading a file.... Read more
Affected Products : cx-programmer- EPSS Score: %0.06
- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-2027
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.... Read more
Affected Products : websphere_extreme_scale- EPSS Score: %0.14
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1933
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX001 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Managemen... Read more
Affected Products : maximo_asset_management maximo_for_life_sciences maximo_for_nuclear_power maximo_for_oil_and_gas maximo_for_transportation maximo_for_utilities smartcloud_control_desk change_and_configuration_management_database maximo_asset_management_essentials maximo_for_government +3 more products- EPSS Score: %0.08
- Published: Oct. 04, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-4077
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.... Read more
Affected Products : forticlient- EPSS Score: %0.56
- Published: Sep. 03, 2015
- Modified: Apr. 12, 2025