Latest CVE Feed
-
2.1
LOWCVE-1999-1294
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permiss... Read more
Affected Products : windows_nt- EPSS Score: %0.64
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-5483
p1003_1b.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by setting a scheduler policy, which should only be settable by root.... Read more
Affected Products : freebsd- EPSS Score: %0.25
- Published: Oct. 24, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-0234
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consume... Read more
Affected Products : netscreen_screenos- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0585
A Windows NT administrator account has the default name of Administrator.... Read more
- EPSS Score: %0.75
- Published: Jul. 01, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6385
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.... Read more
Affected Products : winroute_firewall- EPSS Score: %0.07
- Published: Dec. 15, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-0636
Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to watched files."... Read more
Affected Products : incron- EPSS Score: %0.08
- Published: Jan. 31, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-6340
Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain cleartext passwords.... Read more
- EPSS Score: %0.07
- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-3337
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.... Read more
Affected Products : database_server- EPSS Score: %0.07
- Published: Jun. 22, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-0992
Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : ignition- EPSS Score: %0.06
- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2000-0928
WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.... Read more
Affected Products : diskadvisor- EPSS Score: %0.11
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-1744
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent users to affect availability via unknown vectors related to Outside In Filters.... Read more
Affected Products : fusion_middleware- EPSS Score: %4.64
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-9740
Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are no... Read more
Affected Products : rules_link- EPSS Score: %0.21
- Published: Jul. 06, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-1023
Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, in... Read more
- EPSS Score: %0.06
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1218
Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.... Read more
Affected Products : amiga_unix- EPSS Score: %0.16
- Published: Feb. 18, 1993
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3159
pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns th... Read more
- EPSS Score: %0.08
- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-0859
The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with physical access to obtain sensitive information (memory contents) by doing (1) text searches or (2) paste operations after pressing certai... Read more
Affected Products : treo- EPSS Score: %0.12
- Published: Feb. 16, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-4940
Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain sensitive information by reading this file.... Read more
- EPSS Score: %0.12
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-1999-0144
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.... Read more
Affected Products : qmail- EPSS Score: %1.99
- Published: Jun. 01, 1997
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0355
netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.... Read more
Affected Products : irix- EPSS Score: %0.16
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1822
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.8 allow remote authenticated users with administrator privileges to inject arbitrary web script or HTML via the (1) quota parameter to /core/settings/ajax/setquota.php, or re... Read more
- EPSS Score: %0.18
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025