Latest CVE Feed
-
2.1
LOWCVE-2012-0800
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by acc... Read more
Affected Products : moodle- EPSS Score: %0.07
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-5482
ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX.... Read more
Affected Products : freebsd- EPSS Score: %0.24
- Published: Oct. 24, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-5056
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then... Read more
Affected Products : otrs- EPSS Score: %0.16
- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-5806
SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session information in a directory outside of the CSD vault and does not restrict the user from saving f... Read more
Affected Products : secure_desktop- EPSS Score: %0.09
- Published: Nov. 08, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-2023
The get_parameter_from_freqency_source function in beep2 1.0, 1.1 and 1.2, when installed setuid root, allows local users to read arbitrary files via unknown attack vectors.... Read more
Affected Products : shingo_beep2- EPSS Score: %0.06
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-1996
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.... Read more
- EPSS Score: %0.06
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-5189
Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with permissions to "update Webform nodes" to inject arbitrary web script or HTML via ... Read more
- EPSS Score: %0.25
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-0976
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained fr... Read more
Affected Products : silverstripe- EPSS Score: %0.38
- Published: Feb. 02, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-1346
The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.... Read more
Affected Products : solaris- EPSS Score: %0.09
- Published: Jun. 19, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2723
NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.... Read more
Affected Products : nessuswx- EPSS Score: %0.07
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0442
Solaris ff.core allows local users to modify files.... Read more
- EPSS Score: %0.15
- Published: Jan. 07, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-2127
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.... Read more
Affected Products : integrity_protection_driver- EPSS Score: %0.08
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-6126
Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.... Read more
- EPSS Score: %0.09
- Published: Nov. 27, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-2321
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.... Read more
Affected Products : weblogic_server- EPSS Score: %0.03
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2419
Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on the local system.... Read more
Affected Products : digital_media_server- EPSS Score: %0.08
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0741
Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.... Read more
Affected Products : hsrp- EPSS Score: %1.91
- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-1295
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."... Read more
- EPSS Score: %0.06
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0852
Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.... Read more
Affected Products : windows_xp- EPSS Score: %0.16
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-3601
vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' calendar activities via a (1) home page or (2) event list view.... Read more
Affected Products : vtiger_crm- EPSS Score: %0.22
- Published: Jul. 06, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-3272
EMC Replication Manager (RM) before 5.4.4 places encoded passwords in application log files, which makes it easier for local users to obtain sensitive information by reading a file and conducting an unspecified decoding attack.... Read more
Affected Products : replication_manager- EPSS Score: %0.06
- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025