Latest CVE Feed
-
2.1
LOWCVE-2008-5417
HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) S... Read more
- EPSS Score: %0.08
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-3426
Unspecified vulnerability in the Solaris Platform Information and Control Library daemon (picld) in Sun Solaris 8 through 10, and OpenSolaris builds snv_01 through snv_95, allows local users to cause a denial of service via unknown vectors that prevent op... Read more
- EPSS Score: %0.07
- Published: Jul. 31, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-2159
Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information.... Read more
Affected Products : internet_explorer- EPSS Score: %0.84
- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-3720
The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that re... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-4394
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows local users to delete of arbitrary files via unknown vectors.... Read more
- EPSS Score: %0.04
- Published: Aug. 17, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-2002
Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with "administer words filtered" privileges, to inject arbitrary web script or HTML via the word list... Read more
- EPSS Score: %0.23
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1997
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.... Read more
Affected Products : saurus_cms- EPSS Score: %0.46
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-3380
Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.... Read more
- EPSS Score: %0.17
- Published: Aug. 31, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1976
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb dis... Read more
- EPSS Score: %0.25
- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1294
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.... Read more
Affected Products : coldfusion- EPSS Score: %0.15
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-1234
load_elf_binary in Linux before 2.4.26 allows local users to cause a denial of service (system crash) via an ELF binary in which the interpreter is NULL.... Read more
Affected Products : linux_kernel- EPSS Score: %0.10
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2520
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords.... Read more
Affected Products : mac_os_x- EPSS Score: %0.08
- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-1319
The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is locked, which allows physically proximate attackers to mount removable media while the screen i... Read more
Affected Products : ubuntu_linux- EPSS Score: %0.06
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-5724
Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.... Read more
Affected Products : phpbb3- EPSS Score: %0.04
- Published: Sep. 12, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-2203
The hfs_find_init function in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and Oops) by mounting an HFS file system with a malformed MDB extent record.... Read more
Affected Products : linux_kernel- EPSS Score: %0.14
- Published: Jan. 27, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-0201
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files.... Read more
Affected Products : rhevm-reports- EPSS Score: %0.04
- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5021
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.... Read more
Affected Products : drupal- EPSS Score: %0.18
- Published: Jul. 22, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-2190
The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determine admin passwords via a brute-force attack.... Read more
Affected Products : cherokee- EPSS Score: %0.07
- Published: Oct. 07, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-3109
The HFS and HFS+ (hfsplus) modules in Linux 2.6 allow attackers to cause a denial of service (oops) by using hfsplus to mount a filesystem that is not hfsplus.... Read more
- EPSS Score: %0.07
- Published: Sep. 30, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3108
mm/ioremap.c in Linux 2.6 on 64-bit x86 systems allows local users to cause a denial of service or an information leak via an ioremap on a certain memory map that causes the iounmap to perform a lookup of a page that does not exist.... Read more
- EPSS Score: %0.07
- Published: Sep. 30, 2005
- Modified: Apr. 03, 2025