Latest CVE Feed
-
2.1
LOWCVE-2005-3021
image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.... Read more
Affected Products : vbulletin- EPSS Score: %0.20
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-2724
Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified... Read more
- EPSS Score: %0.18
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-5509
aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.... Read more
- EPSS Score: %0.10
- Published: Mar. 12, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-4377
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with the "create petition" permission to inject arbitrary web script or HTML via unknow... Read more
Affected Products : petition- EPSS Score: %0.21
- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-5448
HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : asset_manager- EPSS Score: %0.06
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-8537
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading the logs.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.06
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-0757
The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not properly handle certain offsets, which allows local users to cause a denial of service (system crash) via certain actions on an ext3 file system with exten... Read more
- EPSS Score: %0.06
- Published: May. 18, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1394
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a d... Read more
Affected Products : bsd- EPSS Score: %0.90
- Published: Jul. 02, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1423
ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.... Read more
- EPSS Score: %0.33
- Published: Jun. 26, 1997
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1784
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Clean Theme before 7.x-1.3 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.23
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-1050
Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information i... Read more
Affected Products : kwik-pay_payroll- EPSS Score: %0.03
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1977
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.... Read more
Affected Products : devstack- EPSS Score: %0.11
- Published: May. 21, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2001-1503
The finger daemon (in.fingerd) in Sun Solaris 2.5 through 8 and SunOS 5.5 through 5.8 allows remote attackers to list all accounts on a host by typing finger 'a b c d e f g h'@host.... Read more
- EPSS Score: %0.22
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-5495
Cross-site scripting (XSS) vulnerability in the Mobile sliding menu module 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer menu" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : mobile_sliding_menu- EPSS Score: %0.21
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-3361
Cross-site scripting (XSS) vulnerability in the Linkit module before 7.x-2.7 and 7.x-3.x before 7.x-3.3 for Drupal, when the node search plugin is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
- EPSS Score: %0.21
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-4176
AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.... Read more
Affected Products : award_bios_modular- EPSS Score: %0.94
- Published: Dec. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-5325
Multiple cross-site scripting (XSS) vulnerabilities in the scr_do_redirect function in scr.php in the Shortcode Redirect plugin 1.0.01 and earlier for WordPress allow remote authenticated users with certain permissions to inject arbitrary web script or HT... Read more
- EPSS Score: %0.11
- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-1448
The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service (disabled interface) by calling an unspecified RPC function.... Read more
- EPSS Score: %1.35
- Published: Mar. 16, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-2070
Cross-site scripting (XSS) vulnerability in the MultiBlock module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer blocks permission to inject arbitrary web script or HTML via the block tit... Read more
- EPSS Score: %0.45
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4577
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.... Read more
- EPSS Score: %0.16
- Published: May. 12, 2014
- Modified: Apr. 12, 2025