Latest CVE Feed
-
2.1
LOWCVE-2012-5179
The Boat Browser application before 4.2 and Boat Browser Mini application before 3.9 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.... Read more
- EPSS Score: %0.06
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1294
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.... Read more
Affected Products : coldfusion- EPSS Score: %0.15
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4383
Cross-site scripting (XSS) vulnerability in the jQuery Countdown module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.21
- Published: Jan. 31, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1997
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.... Read more
Affected Products : saurus_cms- EPSS Score: %0.46
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-7261
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which might allow local users to obtain sensitive information by reading this fil... Read more
Affected Products : filenet_p8_application_engine- EPSS Score: %0.05
- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-4497
Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via a slide UR... Read more
- EPSS Score: %0.34
- Published: Nov. 02, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-0384
Tor 0.2.2.x before 0.2.2.7-alpha, when functioning as a directory mirror, does not prevent logging of the client IP address upon detection of erroneous client behavior, which might make it easier for local users to discover the identities of clients in op... Read more
- EPSS Score: %0.06
- Published: Jan. 25, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-3277
The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web... Read more
- EPSS Score: %0.10
- Published: Sep. 28, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-4142
The Web Search feature in EMC SourceOne Email Management 6.5 before 6.5.2.4033, 6.6 before 6.6.1.2194, and 6.7 before 6.7.2.2033 places cleartext credentials in log files, which allows local users to obtain sensitive information by reading these files.... Read more
Affected Products : sourceone_email_management- EPSS Score: %0.06
- Published: Jan. 19, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-1578
EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection.... Read more
Affected Products : encase- EPSS Score: %0.07
- Published: May. 13, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-0260
Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.... Read more
- EPSS Score: %0.06
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-5585
Cross-site scripting (XSS) vulnerability in the Mixpanel module 6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via the Maxpanel token.... Read more
- EPSS Score: %0.34
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-3191
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect availability via unknown vectors related to Data Mover.... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.45
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-3976
The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not prop... Read more
- EPSS Score: %0.18
- Published: Mar. 26, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6181
EMC Watch4Net before 6.3 stores cleartext polled-device passwords in the installation repository, which allows local users to obtain sensitive information by leveraging repository privileges.... Read more
Affected Products : watch4net- EPSS Score: %0.14
- Published: Dec. 28, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2913
The Citibank Citi Mobile app before 2.0.3 for iOS stores account data in a file, which allows local users to obtain sensitive information via vectors involving (1) the mobile device or (2) a synchronized computer.... Read more
- EPSS Score: %0.06
- Published: Jul. 30, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0085
JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source ... Read more
- EPSS Score: %0.14
- Published: Apr. 17, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-6108
HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations.... Read more
Affected Products : linux_imaging_and_printing_project- EPSS Score: %0.06
- Published: Feb. 15, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-2796
The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password.... Read more
Affected Products : iphone_os- EPSS Score: %0.07
- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-2975
Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow key failure," aka Bug ID CSCtg51544.... Read more
Affected Products : unified_wireless_network_solution_software- EPSS Score: %0.15
- Published: Aug. 10, 2010
- Modified: Apr. 11, 2025