Latest CVE Feed
-
2.1
LOWCVE-2013-1977
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.... Read more
Affected Products : devstack- EPSS Score: %0.11
- Published: May. 21, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-5509
aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.... Read more
- EPSS Score: %0.10
- Published: Mar. 12, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-4787
AlphaMail before 1.0.16 allows local users to obtain sensitive information via the logging functionality, which displays unencrypted passwords in an error message. NOTE: some details are obtained from third party information.... Read more
Affected Products : alphamail- EPSS Score: %0.08
- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4176
AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.... Read more
Affected Products : award_bios_modular- EPSS Score: %0.94
- Published: Dec. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-5448
HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : asset_manager- EPSS Score: %0.06
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-6414
Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from anot... Read more
Affected Products : telepresence_video_communication_server_software- EPSS Score: %0.04
- Published: Dec. 13, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-2070
Cross-site scripting (XSS) vulnerability in the MultiBlock module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer blocks permission to inject arbitrary web script or HTML via the block tit... Read more
- EPSS Score: %0.45
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-1050
Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information i... Read more
Affected Products : kwik-pay_payroll- EPSS Score: %0.03
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1784
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Clean Theme before 7.x-1.3 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.23
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-5325
Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect plugin 1.0.01 and earlier for WordPress allow remote authenticated users with certain permissions to inject arbitrary web script or HT... Read more
- EPSS Score: %0.11
- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4577
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.... Read more
- EPSS Score: %0.16
- Published: May. 12, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-1659
Cross-site scripting (XSS) vulnerability in the Node Recommendation module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.27
- Published: Sep. 18, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-3361
Cross-site scripting (XSS) vulnerability in the Linkit module before 7.x-2.7 and 7.x-3.x before 7.x-3.3 for Drupal, when the node search plugin is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
- EPSS Score: %0.21
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-2000
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspeci... Read more
- EPSS Score: %0.26
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2724
Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified... Read more
- EPSS Score: %0.18
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-1877
tss 0.8.1 allows local users to read arbitrary files via the -a parameter, which is processed while tss is running with privileges.... Read more
Affected Products : tss- EPSS Score: %0.06
- Published: Apr. 17, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-1205
nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.... Read more
Affected Products : hp-ux- EPSS Score: %0.32
- Published: Jun. 07, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0464
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.... Read more
Affected Products : tripwire- EPSS Score: %0.08
- Published: Jan. 04, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-5495
Cross-site scripting (XSS) vulnerability in the Mobile sliding menu module 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer menu" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mobile_sliding_menu- EPSS Score: %0.21
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4820
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.... Read more
- EPSS Score: %0.19
- Published: Sep. 23, 2013
- Modified: Apr. 11, 2025