Latest CVE Feed
-
2.1
LOWCVE-2007-3024
libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allow local users to read sensitive files.... Read more
- EPSS Score: %0.06
- Published: Jun. 07, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-0971
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4... Read more
Affected Products : atutor- EPSS Score: %1.07
- Published: Mar. 16, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-2494
kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.... Read more
Affected Products : linux_kernel- EPSS Score: %0.12
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-3262
tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in t... Read more
Affected Products : xen- EPSS Score: %0.10
- Published: Aug. 19, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-0813
Wicd before 1.7.1 saves sensitive information in log files in /var/log/wicd, which allows context-dependent attackers to obtain passwords and other sensitive information.... Read more
Affected Products : wicd- EPSS Score: %0.07
- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-2527
The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.... Read more
Affected Products : qemu- EPSS Score: %0.09
- Published: Jun. 21, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-4377
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with the "create petition" permission to inject arbitrary web script or HTML via unknow... Read more
Affected Products : petition- EPSS Score: %0.21
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-1659
Cross-site scripting (XSS) vulnerability in the Node Recommendation module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.27
- Published: Sep. 18, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-5659
PAM_extern before 0.2 sends a password as a command line argument, which allows local users to obtain the password by listing the command line arguments, such as ps. NOTE: the provenance of this information is unknown; the details are obtained solely fro... Read more
Affected Products : pam_extern- EPSS Score: %0.06
- Published: Nov. 03, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-0095
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web, a different vulnerability than CVE-2012... Read more
Affected Products : fusion_middleware- EPSS Score: %0.14
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-1783
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspe... Read more
- EPSS Score: %0.35
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4820
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.... Read more
- EPSS Score: %0.19
- Published: Sep. 23, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-1652
Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via unspecified vectors related to "... Read more
- EPSS Score: %0.27
- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-3669
Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users.... Read more
Affected Products : mercury_messenger- EPSS Score: %0.05
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1000
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.... Read more
Affected Products : lintian- EPSS Score: %0.06
- Published: Jan. 10, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1029
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alterna... Read more
- EPSS Score: %0.13
- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0169
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /li... Read more
- EPSS Score: %0.14
- Published: Mar. 26, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0147
snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host's configuration.... Read more
Affected Products : openserver- EPSS Score: %0.13
- Published: Feb. 08, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0336
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.04
- Published: Apr. 21, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-2585
Unspecified vulnerability in the Application Express component in Oracle Database Server before 5.0 allows remote authenticated users to affect availability via unknown vectors.... Read more
Affected Products : database_server- EPSS Score: %0.36
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025