Latest CVE Feed
-
2.1
LOWCVE-2014-0647
The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-m... Read more
- EPSS Score: %0.08
- Published: Jan. 28, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2019-4048
IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previous user of the same machine. IBM X-Force ID: 156311.... Read more
- EPSS Score: %0.08
- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
2.1
LOWCVE-2012-1744
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent users to affect availability via unknown vectors related to Outside In Filters.... Read more
Affected Products : fusion_middleware- EPSS Score: %4.64
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-1999-1314
Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.... Read more
Affected Products : freebsd- EPSS Score: %0.06
- Published: May. 17, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0234
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consume... Read more
Affected Products : netscreen_screenos- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-1970
muCommander before 0.8.2 stores credentials.xml with insecure permissions, which allows local users to obtain credentials.... Read more
Affected Products : mucommander- EPSS Score: %0.05
- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-3337
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.... Read more
Affected Products : database_server- EPSS Score: %0.07
- Published: Jun. 22, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-1554
/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.... Read more
Affected Products : irix- EPSS Score: %0.90
- Published: Oct. 31, 1990
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2683
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server.... Read more
Affected Products : cache- EPSS Score: %0.06
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-1996
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with certain creation privileges, to inject arbitrary web script or HTML via the (1) content parameter in conjunction with a /admi... Read more
Affected Products : tomatocms- EPSS Score: %0.46
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-1822
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.8 allow remote authenticated users with administrator privileges to inject arbitrary web script or HTML via the (1) quota parameter to /core/settings/ajax/setquota.php, or re... Read more
- EPSS Score: %0.18
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2001-0417
Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.... Read more
- EPSS Score: %0.11
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0105
Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.... Read more
Affected Products : hp-ux- EPSS Score: %0.27
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-0992
Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : ignition- EPSS Score: %0.06
- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2003-1476
Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.... Read more
Affected Products : ftp_server- EPSS Score: %0.06
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0355
netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.... Read more
Affected Products : irix- EPSS Score: %0.16
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3785
Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the window using tools such as Nirsoft ... Read more
Affected Products : pcanywhere- EPSS Score: %0.08
- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0261
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.... Read more
Affected Products : windows_2000- EPSS Score: %1.10
- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0510
The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.... Read more
Affected Products : fallback-reboot- EPSS Score: %0.06
- Published: Mar. 14, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0114
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort funct... Read more
- EPSS Score: %0.06
- Published: Feb. 11, 2005
- Modified: Apr. 03, 2025