Latest CVE Feed
-
2.1
LOWCVE-2004-1895
YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.... Read more
Affected Products : suse_linux- EPSS Score: %0.08
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-3093
IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the installation process, (4) environment checks, (5) powervc-ldap-config, (6) powervc-restore, and (7) powervc-diag, which allows local u... Read more
Affected Products : powervc- EPSS Score: %0.05
- Published: Aug. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-1500
PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user's home directory, which allows local users to obtain Pandora credentials by reading this file.... Read more
Affected Products : pithos- EPSS Score: %0.05
- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-4835
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.... Read more
- EPSS Score: %0.05
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-2731
Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. (dot dot) in the wfe_download parameter to index.fpl.... Read more
Affected Products : security_linux- EPSS Score: %0.12
- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2011-1742
EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain sensitive information by reading this file.... Read more
Affected Products : data_protection_advisor- EPSS Score: %0.08
- Published: Aug. 01, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-6744
Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified ... Read more
Affected Products : installshield- EPSS Score: %0.06
- Published: Jan. 19, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-5429
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it ... Read more
Affected Products : tivoli_federated_identity_manager- EPSS Score: %0.18
- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-5398
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XM... Read more
Affected Products : wonderware_information_server- EPSS Score: %0.11
- Published: Aug. 28, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-6117
Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.... Read more
- EPSS Score: %0.10
- Published: Mar. 12, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-1951
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by levera... Read more
Affected Products : maximo_asset_management- EPSS Score: %0.06
- Published: Jul. 01, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-7064
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML vi... Read more
Affected Products : eu_cookie_compliance- EPSS Score: %0.20
- Published: Apr. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-2612
Unspecified vulnerability in the HP OpenVMS Auditing feature in OpenVMS ALPHA 7.3-2, 8.2, and 8.3; and OpenVMS for Integrity Servers 8.3 AND 8.3-1H1; allows local users to obtain sensitive information via unknown vectors.... Read more
- EPSS Score: %0.13
- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-2105
Microsoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file.... Read more
Affected Products : windows_xp- EPSS Score: %0.39
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1378
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.... Read more
Affected Products : fetchmail- EPSS Score: %0.05
- Published: Sep. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-1958
Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitra... Read more
- EPSS Score: %0.25
- Published: Jun. 21, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-2368
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by rea... Read more
Affected Products : certificate_system- EPSS Score: %0.03
- Published: Jan. 20, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2011-0652
lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 and 2.07 allows local users to cause a denial of service (crash) via a crafted 0x80000064 IOCTL request that triggers an assertion failure. NOTE: some of these details are obtained from third part... Read more
Affected Products : look_\'n\'_stop_firewall- EPSS Score: %0.23
- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-5790
The Globe7 soft phone client 7.3 uses weak cryptography (reversed sequence of binary values) for the password, which might allow local users to obtain sensitive information.... Read more
Affected Products : globe7- EPSS Score: %0.07
- Published: Nov. 01, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-0889
Red Hat Directory Server 8.0, when running on Red Hat Enterprise Linux, uses insecure permissions for the redhat-idm-console script, which allows local users to execute arbitrary code by modifying the script.... Read more
- EPSS Score: %0.07
- Published: Mar. 20, 2008
- Modified: Apr. 09, 2025