Latest CVE Feed
-
2.1
LOWCVE-2012-0800
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by acc... Read more
Affected Products : moodle- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-8537
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading the logs.... Read more
Affected Products : network_data_loss_prevention- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-1659
Cross-site scripting (XSS) vulnerability in the Node Recommendation module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 18, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4820
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.... Read more
- Published: Sep. 23, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2024-9101
A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the latest version, 1.2.6.7) allows attackers to execute arbitrary JavaScript in the user's browser via the 'element' parameter, which is un... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
2.1
LOWCVE-2025-27512
Zincati is an auto-update agent for Fedora CoreOS hosts. Zincati ships a polkit rule which allows the `zincati` system user to use the actions `org.projectatomic.rpmostree1.deploy` to deploy updates to the system and `org.projectatomic.rpmostree1.finalize... Read more
Affected Products :- Published: Mar. 17, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authorization
-
2.1
LOWCVE-2001-0079
Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.... Read more
Affected Products : support_tools_manager- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-0996
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it ea... Read more
- Published: Mar. 29, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2001-0069
dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : debian_linux- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-1951
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by levera... Read more
Affected Products : maximo_asset_management- Published: Jul. 01, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2001-1302
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a prob... Read more
Affected Products : windows_2000- Published: Jul. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-5819
IBM Tivoli Continuous Data Protection for Files (CDP) 3.1.0 uses weak permissions (unrestricted write) for the Central Admin Global download directory, which allows local users to place arbitrary files into a location used for updating CDP clients.... Read more
Affected Products : tivoli_continuous_data_protection_for_files- Published: Nov. 05, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2005-1932
Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arb... Read more
Affected Products : lpanel- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0622
Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive inform... Read more
Affected Products : mac_os_x- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-6754
Cross-site scripting (XSS) vulnerability in the administration interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "Administer Path Breadcrumbs" permission to inject arbitrary web script or... Read more
Affected Products : path_breadcrumbs- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5400
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.... Read more
Affected Products : mednet- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2001-1122
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.... Read more
Affected Products : windows_nt- Published: Aug. 03, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-1358
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspeci... Read more
- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-7020
McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memo... Read more
Affected Products : safeboot_device_encryption- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-1487
IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.... Read more
- Published: Apr. 20, 2010
- Modified: Apr. 11, 2025