Latest CVE Feed
-
2.1
LOWCVE-2014-8536
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading unspecified error messages.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.06
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-0384
Tor 0.2.2.x before 0.2.2.7-alpha, when functioning as a directory mirror, does not prevent logging of the client IP address upon detection of erroneous client behavior, which might make it easier for local users to discover the identities of clients in op... Read more
- EPSS Score: %0.06
- Published: Jan. 25, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-3897
DiskCryptor 0.2.6 on Windows stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associ... Read more
- EPSS Score: %0.06
- Published: Sep. 03, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-1431
RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.... Read more
- EPSS Score: %0.04
- Published: Mar. 20, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-4394
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows local users to delete of arbitrary files via unknown vectors.... Read more
- EPSS Score: %0.04
- Published: Aug. 17, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2024-31747
An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximate attacker to disable the phone lock via the Walkie Talkie menu option.... Read more
Affected Products : vp59_firmware- Published: Apr. 29, 2024
- Modified: Jul. 30, 2025
-
2.1
LOWCVE-2006-6656
Unspecified vulnerability in ptrace in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read kernel memory and obtain sensitive information via certain manipulations of a PT_LWPINFO... Read more
Affected Products : netbsd- EPSS Score: %0.06
- Published: Dec. 20, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2000-0879
LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.... Read more
Affected Products : lpplus- EPSS Score: %0.06
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-8733
Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.... Read more
Affected Products : cloudera_manager- EPSS Score: %0.06
- Published: Feb. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9418
The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users to cause a denial of service (memory overflow) via unspecified vectors.... Read more
Affected Products : espace_desktop- EPSS Score: %0.23
- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-6131
buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.... Read more
Affected Products : fedora_core- EPSS Score: %0.07
- Published: Nov. 26, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2005-2990
AuthInfo.java in LineContol Java Client (jlc) before 0.8.1 stores sensitive information such as user passwords in log files.... Read more
Affected Products : java_client- EPSS Score: %0.06
- Published: Sep. 20, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-1640
Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1... Read more
- EPSS Score: %0.25
- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-1234
The paratrooper-newrelic gem 1.0.1 for Ruby allows local users to obtain the X-Api-Key value by listing the curl process.... Read more
Affected Products : paratrooper-newrelic- EPSS Score: %0.08
- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2000-0334
The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.... Read more
Affected Products : spectra- EPSS Score: %0.10
- Published: Apr. 24, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1968
Com21 DOXport 1100 series cable modem running firmware 2.1.1.106, and possibly other versions before 2.1.1.108.003, downloads a DOCSIS configuration file from a TFTP server running on the internal network, which allows local users to modify configuration ... Read more
Affected Products : doxport_1100- EPSS Score: %0.07
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1671
The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which... Read more
Affected Products : messenger- EPSS Score: %0.03
- Published: May. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-2051
The processor_web plugin for ModLogAn 0.5.0 through 0.7.11, when used with the splitby option, allows local users to overwrite arbitrary files via a symlink attack on files specified as hostnames in a log file.... Read more
Affected Products : modlogan- EPSS Score: %0.15
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0828
The ctstrtcasd program in RSCT 2.3.0.0 and earlier on IBM AIX 5.2 and 5.3 does not properly drop privileges before executing the -f option, which allows local users to modify or create arbitrary files.... Read more
Affected Products : aix- EPSS Score: %0.08
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0227
The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.... Read more
- EPSS Score: %0.17
- Published: Mar. 23, 2000
- Modified: Apr. 03, 2025