Latest CVE Feed
-
2.1
LOWCVE-2001-1378
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.... Read more
Affected Products : fetchmail- Published: Sep. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0887
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.... Read more
Affected Products : openserver- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0790
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.... Read more
Affected Products : aix- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-6583
Cross-site scripting (XSS) vulnerability in the Imagemenu module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer imagemenu" permission to inject arbitrary web script or HTML via an image file name.... Read more
- Published: Aug. 23, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-0619
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.... Read more
Affected Products : einstein- Published: Feb. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1956
The create_user_ns function in kernel/user_namespace.c in the Linux kernel before 3.8.6 does not check whether a chroot directory exists that differs from the namespace root directory, which allows local users to bypass intended filesystem restrictions vi... Read more
Affected Products : linux_kernel- Published: Apr. 24, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-5429
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it ... Read more
Affected Products : tivoli_federated_identity_manager- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-4824
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-4526
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.... Read more
- Published: Aug. 25, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-2201
The screensharing feature in the Admin application in Apple Xsan before 2.2 places a cleartext username and password in a URL within an error dialog, which allows physically proximate attackers to obtain credentials by reading this dialog.... Read more
Affected Products : xsan- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2014-0647
The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-m... Read more
- Published: Jan. 28, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-6147
IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sensitive information, and consequently gain privileges or conduct impersonation attacks, via unspecified vectors.... Read more
Affected Products : flex_system_manager- Published: Feb. 19, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-6128
The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performed.... Read more
Affected Products : linux_kernel- Published: Nov. 27, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-0223
Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.... Read more
Affected Products : sunos- Published: Mar. 01, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0121
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.... Read more
Affected Products : php- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2025-53535
Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-lin... Read more
Affected Products : better_auth- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
2.1
LOWCVE-2014-4835
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-1588
The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.... Read more
Affected Products : netbsd- Published: Apr. 03, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-4380
Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web s... Read more
- Published: May. 20, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-1999-1494
colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.... Read more
Affected Products : irix- Published: Aug. 09, 1994
- Modified: Apr. 03, 2025