Latest CVE Feed
-
2.1
LOWCVE-2015-1005
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : scada_web_server- EPSS Score: %0.06
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-1999-0803
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.... Read more
Affected Products : aix_enetwork_firewall- EPSS Score: %2.71
- Published: May. 25, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0055
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.... Read more
Affected Products : freebsd- EPSS Score: %0.07
- Published: Jan. 11, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0077
Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.... Read more
Affected Products : file_extattr- EPSS Score: %0.09
- Published: Jan. 04, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1197
POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for ot... Read more
Affected Products : imap- EPSS Score: %0.08
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1429
DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.... Read more
Affected Products : transferpro- EPSS Score: %0.08
- Published: Jan. 05, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0712
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of a master user, which could allow a master user to perform operations that require multiple authorizations.... Read more
Affected Products : entrust_authority_security_manager- EPSS Score: %0.25
- Published: Feb. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-4503
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options.... Read more
Affected Products : feed_element_mapper- EPSS Score: %0.18
- Published: May. 13, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2000-0754
Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %0.24
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0069
The recover program in Solstice Backup allows local users to restore sensitive files.... Read more
Affected Products : solstice_backup- EPSS Score: %0.12
- Published: Jan. 01, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1285
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Dec. 27, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-5233
Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.... Read more
- EPSS Score: %0.32
- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2000-0458
The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.... Read more
Affected Products : imp- EPSS Score: %0.12
- Published: Apr. 22, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6150
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that... Read more
Affected Products : freebsd- EPSS Score: %0.07
- Published: Nov. 30, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-1137
The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.... Read more
- EPSS Score: %0.08
- Published: Oct. 01, 1993
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1564
FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes.... Read more
Affected Products : freebsd- EPSS Score: %0.06
- Published: Sep. 02, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-5538
Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script... Read more
- EPSS Score: %0.20
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-4352
Address Book in Apple iOS before 8 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.... Read more
Affected Products : iphone_os- EPSS Score: %0.04
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-0492
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120... Read more
- EPSS Score: %0.55
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-1679
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to bypass the ASLR p... Read more
- EPSS Score: %2.99
- Published: May. 13, 2015
- Modified: Apr. 12, 2025