Latest CVE Feed
-
2.1
LOWCVE-2007-4898
Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users, with administrative access to one wiki in a multiwiki environment, to obtain sensitive information via unknown attack vectors. NOTE: S... Read more
Affected Products : xwiki- EPSS Score: %0.05
- Published: Sep. 14, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-2276
F-Secure Anti-Virus 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlier for Linux does not properly detect certain viruses in a PKZip archive, which allows viruses such as Sober.D and Sober.G to bypass ini... Read more
Affected Products : f-secure_anti-virus- EPSS Score: %0.10
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2258
Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab.... Read more
Affected Products : exceed- EPSS Score: %0.08
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1795
Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.... Read more
Affected Products : surfnet- EPSS Score: %0.06
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-1191
The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library/Logs/Console/UID/Console.log file, which allows local users to obtain sensitive information by reading this file.... Read more
Affected Products : del.icio.us_module- EPSS Score: %0.07
- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-0370
The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.... Read more
Affected Products : freebsd- EPSS Score: %0.08
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0341
WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.... Read more
Affected Products : wftpd- EPSS Score: %0.15
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3250
Unknown vulnerability in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors related to the "/proc" filesystem, which trigger a null dereference.... Read more
Affected Products : solaris- EPSS Score: %0.06
- Published: Oct. 17, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-0009
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.... Read more
Affected Products : linux_kernel- EPSS Score: %1.00
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2005-3124
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : thttpd- EPSS Score: %0.10
- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2100
The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).... Read more
- EPSS Score: %0.06
- Published: Oct. 25, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3121
A rule file in module-assistant before 0.9.10 causes a temporary file to be created insecurely, which allows local users to conduct unauthorized operations.... Read more
Affected Products : module-assistant- EPSS Score: %0.07
- Published: Oct. 20, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1785
Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear... Read more
Affected Products : document_server- EPSS Score: %1.36
- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2554
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.... Read more
Affected Products : epolicy_orchestrator_agent- EPSS Score: %0.05
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0422
flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.... Read more
- EPSS Score: %0.08
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0133
The XFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the XFS file system, which allows local users to obtain sensitive information by reading the raw device.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3115
mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN].... Read more
Affected Products : mpeg-tools- EPSS Score: %0.08
- Published: Sep. 30, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6418
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argument, which might allow local users to read the password by listing the process and its arguments.... Read more
Affected Products : debian_linux- EPSS Score: %0.06
- Published: Dec. 18, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-0462
The built-in web servers for multiple networking devices do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session with the same server.... Read more
Affected Products :- EPSS Score: %0.23
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3486
Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local users to cause a denial of service (application crash) via u... Read more
- EPSS Score: %0.10
- Published: Jul. 10, 2006
- Modified: Apr. 03, 2025