Latest CVE Feed
-
2.1
LOWCVE-2006-0077
Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.... Read more
Affected Products : file_extattr- EPSS Score: %0.09
- Published: Jan. 04, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-0663
Novell Challenge Response Client (LCM) 2.7.5 and earlier, as used with Novell Client for Windows 4.91 SP4, allows users with physical access to a locked system to obtain contents of the clipboard by pasting the contents into the Challenge Question field.... Read more
- EPSS Score: %0.08
- Published: Feb. 08, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2000-0387
The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.... Read more
Affected Products : golddig- EPSS Score: %0.11
- Published: May. 09, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2016-3888
internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, ... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-3238
Multiple unspecified vulnerabilities in Solaris 10 SCTP Socket Option Processing allows local users to cause a denial of service (panic) via unspecified attack vectors.... Read more
Affected Products : solaris- EPSS Score: %0.06
- Published: Oct. 14, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-7835
webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site... Read more
Affected Products : moodle- EPSS Score: %0.18
- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4503
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options.... Read more
Affected Products : feed_element_mapper- EPSS Score: %0.18
- Published: May. 13, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5038
Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files.... Read more
Affected Products : eucalyptus- EPSS Score: %0.06
- Published: Nov. 07, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-1346
The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.... Read more
Affected Products : solaris- EPSS Score: %0.09
- Published: Jun. 19, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-6216
Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors.... Read more
- EPSS Score: %0.12
- Published: Apr. 12, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-4273
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.... Read more
Affected Products : aix- EPSS Score: %0.06
- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-1295
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."... Read more
- EPSS Score: %0.06
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0507
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous u... Read more
- EPSS Score: %1.46
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0055
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.... Read more
Affected Products : freebsd- EPSS Score: %0.07
- Published: Jan. 11, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1231
SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc.... Read more
- EPSS Score: %0.06
- Published: Nov. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-5100
Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.... Read more
Affected Products : bi_server- EPSS Score: %0.08
- Published: Sep. 13, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-3929
Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script or HTML via the handler parameter.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.18
- Published: Dec. 09, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-3268
yiff server (yiff-server) 2.14.2 on Debian GNU/Linux runs as root and does not properly verify ownership of files that it opens, which allows local users to read arbitrary files.... Read more
Affected Products : yiff_server- EPSS Score: %0.06
- Published: Oct. 20, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-1539
Cross-site scripting (XSS) vulnerability in the Workflow module 5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when used with the Token module, might allow remote authenticated users to inject arbitrary web script or HTML via a certain Comm... Read more
- EPSS Score: %0.34
- Published: Apr. 26, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-1983
The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.... Read more
Affected Products : rtos- EPSS Score: %0.25
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025