Latest CVE Feed
-
2.1
LOWCVE-2012-1629
Cross-site scripting (XSS) vulnerability in the Taxotouch module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1997
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web script or HTML via the pealkiri parameter.... Read more
Affected Products : saurus_cms- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-2555
Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they k... Read more
Affected Products : foolproof_security- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-5964
Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to inject arbitrary web script or HTML via the flag title.... Read more
- Published: Sep. 30, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-2609
The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer... Read more
Affected Products : powerquest_deploycenter- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0483
OpenBSD crash using nlink value in FFS and EXT2FS filesystems.... Read more
Affected Products : openbsd- Published: Feb. 25, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0417
64 bit Solaris 7 procfs allows local users to perform a denial of service.... Read more
- Published: Mar. 09, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0327
SGI syserr program allows local users to corrupt files.... Read more
Affected Products : irix- Published: Nov. 01, 1997
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1496
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.... Read more
- Published: Jun. 08, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1059
Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.... Read more
Affected Products : wet11- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-3191
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect availability via unknown vectors related to Data Mover.... Read more
Affected Products : peoplesoft_products- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-1999-1400
The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.... Read more
Affected Products : the_economist_1999_screen_saver- Published: Jun. 03, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0743
Trn allows local users to overwrite other users' files via symlinks.... Read more
Affected Products : debian_linux- Published: Aug. 20, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-2002
Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with "administer words filtered" privileges, to inject arbitrary web script or HTML via the word list... Read more
- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-1587
The libthread library (libthread.so.1) for Solaris 2.5.1 through 8 allows local users to cause a denial of service (hang) of an application that uses libthread by causing the application to wait for a certain mutex.... Read more
- Published: Dec. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-6674
Ozeki HTTP-SMS Gateway 1.0, and possibly earlier, stores usernames and passwords in plaintext in the HKLM\Software\Ozeki\SMSServer\CurrentVersion\Plugins\httpsmsgate registry key, which allows local users to obtain sensitive information.... Read more
Affected Products : http-sms_gateway- Published: Dec. 21, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-0957
MajorCool mj_key_cache program allows local users to modify files via a symlink attack.... Read more
Affected Products : majorcool- Published: Jun. 18, 1997
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-5705
Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script ... Read more
- Published: Nov. 01, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-1999-0857
FreeBSD gdc program allows local users to modify files via a symlink attack.... Read more
Affected Products : freebsd- Published: Dec. 01, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-3895
LILO 22.6.1 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated ... Read more
Affected Products : lilo- Published: Sep. 03, 2008
- Modified: Apr. 09, 2025