Latest CVE Feed
-
2.1
LOWCVE-2004-2459
Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.... Read more
Affected Products : gnubiff- EPSS Score: %0.06
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1667
The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to cause a denial of service (crash) by calling msync on an unaccessed memory m... Read more
Affected Products : freebsd- EPSS Score: %0.06
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0261
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.... Read more
Affected Products : windows_2000- EPSS Score: %1.10
- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0421
DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.... Read more
Affected Products : delphiturk_ftp- EPSS Score: %0.15
- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0377
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.... Read more
Affected Products : gaim- EPSS Score: %0.12
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-4293
The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obtain sensitive information by reading the log files.... Read more
Affected Products : jboss_operations_network- EPSS Score: %0.05
- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-1588
The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.... Read more
Affected Products : netbsd- EPSS Score: %0.08
- Published: Apr. 03, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-0124
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : employee_timeclock_software- EPSS Score: %0.06
- Published: Mar. 15, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-3949
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _POSIX_SPAWN_DISABLE_ASLR and _POSIX_SPAWN_ALLOW_DATA_EXEC flags for setuid and setgid programs, which allows local users to bypass intended access restrict... Read more
- EPSS Score: %0.05
- Published: Jun. 05, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2025-43753
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through ... Read more
- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
2.1
LOWCVE-2006-5956
XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.... Read more
Affected Products : phprunner- EPSS Score: %0.08
- Published: Nov. 17, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-1731
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF.... Read more
Affected Products : os_400- EPSS Score: %0.76
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-4218
The InitMethodAndPassword function in InfraStack/OSAgnostic/WiMax/Agents/Supplicant/Source/SupplicantAgent.c in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses the same RSA private key in supplicant_key.... Read more
Affected Products : wimax_network_service- EPSS Score: %0.06
- Published: Aug. 25, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-1764
acroread in Adobe Acrobat Reader 4.05 on Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : acrobat_reader- EPSS Score: %0.20
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0275
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.... Read more
Affected Products : cryptoadmin- EPSS Score: %0.32
- Published: Apr. 10, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-2040
Multiple cross-site scripting (XSS) vulnerabilities in the (1) callback_multicheck, (2) callback_radio, and (3) callback_wysiwygin functions in mfrh_class.settings-api.php in the Media File Renamer plugin 1.7.0 for WordPress allow remote authenticated use... Read more
Affected Products : media_file_renamer- EPSS Score: %0.15
- Published: Mar. 03, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-1999-1010
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.... Read more
Affected Products : openssh- EPSS Score: %0.24
- Published: Dec. 14, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-4238
Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.... Read more
Affected Products : tcexam- EPSS Score: %0.18
- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-2082
Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the post comments permission to inject arbitrary web script or HTML via a user signature.... Read more
Affected Products : ctools- EPSS Score: %0.34
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2000-0019
IMail POP3 daemon uses weak encryption, which allows local users to read files.... Read more
Affected Products : imail- EPSS Score: %0.02
- Published: Mar. 04, 1999
- Modified: Apr. 03, 2025