Latest CVE Feed
-
2.1
LOWCVE-2005-1915
The log4sh_readProperties function in log4sh 1.2.5 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable log4sh.$$ filenames.... Read more
Affected Products : log4sh- EPSS Score: %0.10
- Published: Sep. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0928
WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.... Read more
Affected Products : diskadvisor- EPSS Score: %0.11
- Published: Dec. 19, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1218
Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.... Read more
Affected Products : amiga_unix- EPSS Score: %0.16
- Published: Feb. 18, 1993
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0585
A Windows NT administrator account has the default name of Administrator.... Read more
- EPSS Score: %0.75
- Published: Jul. 01, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1970
SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.... Read more
Affected Products : snortcenter- EPSS Score: %0.05
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0460
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.... Read more
Affected Products : linux_kernel- EPSS Score: %0.19
- Published: Feb. 19, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3785
Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the window using tools such as Nirsoft ... Read more
Affected Products : pcanywhere- EPSS Score: %0.08
- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-0859
The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with physical access to obtain sensitive information (memory contents) by doing (1) text searches or (2) paste operations after pressing certai... Read more
Affected Products : treo- EPSS Score: %0.12
- Published: Feb. 16, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-0234
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consume... Read more
Affected Products : netscreen_screenos- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0355
netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.... Read more
Affected Products : irix- EPSS Score: %0.16
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3159
pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns th... Read more
- EPSS Score: %0.08
- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1550
CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.... Read more
- EPSS Score: %0.18
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-3245
The automated-backup functionality in Blackboard Transact Suite (formerly Blackboard Commerce Suite) stores the (1) database username and (2) database password in cleartext in (a) script and (b) batch (.bat) files, which allows local users to obtain sensi... Read more
Affected Products : transact_suite- EPSS Score: %0.08
- Published: Sep. 07, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2003-0175
SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.... Read more
Affected Products : irix- EPSS Score: %0.10
- Published: Feb. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-3999
Piriform CCleaner 3.26.0.1988 through 5.02.5101 writes the filenames to disk when overwriting files, which allows local users to obtain sensitive information by searching unallocated disk space.... Read more
Affected Products : ccleaner- EPSS Score: %0.04
- Published: May. 20, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-2180
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.... Read more
Affected Products : gnats- EPSS Score: %0.07
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-5914
An unspecified function in the JavaScript implementation in Apple Safari creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up ... Read more
Affected Products : safari- EPSS Score: %0.23
- Published: Jan. 20, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-2412
Winamp 2.80 stores authentication credentials in plaintext in the (1) [HTTP-AUTH] and (2) [winamp] sections in winamp.ini, which allows local users to gain access to other accounts.... Read more
Affected Products : winamp- EPSS Score: %0.13
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2017-18392
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).... Read more
Affected Products : cpanel- EPSS Score: %0.27
- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
2.1
LOWCVE-2009-2918
The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size of ... Read more
Affected Products : thegreenbow_vpn_client- EPSS Score: %0.16
- Published: Aug. 21, 2009
- Modified: Apr. 09, 2025